Skip to content
MLflowGHSA-f2m9-wcf4-cwwx

MLFlow Creates a Temporary File With Insecure Permissions

High7.0CVE-2026-4137 · Published May 18, 2026 · updated Sep 1, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
>= 1.26.0, < 3.11.03.11.0
Details and references

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with group-writable permissions (0o770). These insecure permissions allow local attackers to tamper with model artifacts, such as cloudpickle-serialized Python objects, and achieve arbitrary code execution when the tampered artifacts are deserialized via `cloudpickle.load()`. This vulnerability is particularly critical in environments with shared NFS mounts, such as Databricks, where NFS is enabled by default. The issue is a continuation of the vulnerability class addressed in CVE-2025-10279, which was only partially fixed.

CVSS 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-378
Also known as
BIT-mlflow-2026-4137, CVE-2026-4137, PYSEC-2026-2655

More MLflow advisories

All MLflow
DateAdvisory
May 19MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
CVE-2026-2611Critical9.6fixed in 3.10.0
May 15MLflow: unauthenticated access to certain FastAPI routes
CVE-2026-2652High8.6fixed in 3.11.0
May 21MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
CVE-2026-2734Medium6.5fixed in 3.10.0
May 11MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2026-2614High7.5fixed in 3.10.0
May 11MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-2393High7.1fixed in 3.9.0
May 26MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
CVE-2026-2651Critical9.0fixed in 3.11.0rc1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.