MLflowGHSA-fmxj-6h9g-6vw3
MLflow Path Traversal vulnerability
Critical10.0CVE-2023-3765 · Published Jul 19, 2023 · updated Apr 10, 2025
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.5.0 | 2.5.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-36
- Also known as
- BIT-mlflow-2023-3765, CVE-2023-3765, PYSEC-2023-308
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12023 | mlflow vulnerable to OS Command Injection | High8.8 | 2.6.0 |
| May 172023 | mlflow Path Traversal vulnerability | Critical9.8 | 2.3.0 |
| May 112023 | mflow vulnerable to directory traversal | High7.5 | 2.0.0rc0 |
| May 12023 | Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs | Critical | 2.3.1 |
| Apr 282023 | Relative path traversal in mlflow | High10.0 | 2.3.1 |
| Mar 242023 | Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs | Medium3.3 | 2.2.1 |