Skip to content
MLflowGHSA-f798-qm4r-23r5

MLflow allowed arbitrary files to be PUT onto the server

Critical10.0CVE-2023-6015 · Published Nov 16, 2023 · updated Jun 29, 2026

MLflow allowed arbitrary files to be PUT onto the server.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.8.12.8.1
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
BIT-mlflow-2023-6015, CVE-2023-6015, PYSEC-2026-420

More MLflow advisories

All MLflow
Advisory
Path traversal in MLflow
High8.8Dec 13, 2023
Jinja2 template injection in mlflow
High8.8Dec 12, 2023
Cross-site Scripting (XSS) in MLflow
Medium6.5Dec 7, 2023
Information exposure in MLflow
High7.5Dec 5, 2023
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
Critical9.1Nov 16, 2023
Remote Code Execution due to Full Controled File Write in mlflow
Critical10.0Nov 16, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.