Skip to content
MLflowGHSA-fhff-qmm8-h2fp

Arbitrary file write via tar traversal in mlflow

High8.1CVE-2025-15031 · Published Mar 19, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.9.0rc03.9.0rc0
Details and references

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables crafted tar.gz files containing `..` or absolute paths to escape the intended extraction directory. This issue affects the latest version of MLflow and poses a high/critical risk in scenarios involving multi-tenant environments or ingestion of untrusted artifacts, as it can lead to arbitrary file overwrites and potential remote code execution.

CVSS 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
BIT-mlflow-2025-15031, CVE-2025-15031, PYSEC-2026-2656

More MLflow advisories

All MLflow
DateAdvisory
Mar 16MLflow has a command injection in mlflow/sagemaker/__init__.py
CVE-2025-14287High7.5fixed in 3.8.0rc0
Mar 27MLFlow allows Tracing + Assessments Access
CVE-2025-15381High8.1no fix yet
Mar 30MLFlow path traversal vulnerability
CVE-2025-15036Critical9.6fixed in 3.9.0rc0
Mar 30MLflow Command Injection vulnerability
CVE-2025-15379Critical10.0fixed in 3.8.1
Mar 31Mlflow: Command Injection when serving models with enable_mlserver=True
CVE-2026-0596Critical9.6fixed in 3.9.0
Apr 3mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
CVE-2026-0545Critical9.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.