MLflowGHSA-f798-qm4r-23r5
MLflow allowed arbitrary files to be PUT onto the server
Critical10.0CVE-2023-6015 · Published Nov 16, 2023 · updated Jun 29, 2026
MLflow allowed arbitrary files to be PUT onto the server.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.8.1 | 2.8.1 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- BIT-mlflow-2023-6015, CVE-2023-6015, PYSEC-2026-420
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 132023 | Path traversal in MLflow | High8.8 | 2.9.2 |
| Dec 122023 | Jinja2 template injection in mlflow | High8.8 | 2.9.2 |
| Dec 72023 | Cross-site Scripting (XSS) in MLflow | Medium6.5 | 2.9.0 |
| Dec 52023 | Information exposure in MLflow | High7.5 | 2.9.0 |
| Nov 162023 | MLflow authentication requirement bypass can allow a user to arbitrarily create an account | Critical9.1 | 2.8.0 |
| Nov 162023 | Remote Code Execution due to Full Controled File Write in mlflow | Critical10.0 | 2.9.2 |