Skip to content
MLflowGHSA-fh64-r2vc-xvhr

MLflow: cross-site scripting

Medium5.4CVE-2026-33865 · Published Apr 7, 2026 · updated Sep 10, 2026

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows actions such as session hijacking or performing operations on behalf of the victim. This issue affects MLflow version through 3.10.1

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.11.13.11.1
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
Medium4.3Apr 7
MLflow: remote code execution
Critical9.1Apr 3
Mlflow: Command Injection when serving models with enable_mlserver=True
Critical9.6Mar 31
MLflow Command Injection vulnerability
Critical10.0Mar 30
MLFlow path traversal vulnerability
Critical9.6Mar 30
MLFlow allows Tracing + Assessments Access
High8.1Mar 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.