Skip to content
MLflowGHSA-g6pg-52vf-843h

MLFlow allows Tracing + Assessments Access

High8.1CVE-2025-15381 · Published Mar 27, 2026 · updated Sep 10, 2026

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
<= 3.8.1No fix yet
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow: remote code execution
Critical9.1Apr 3
Mlflow: Command Injection when serving models with enable_mlserver=True
Critical9.6Mar 31
MLflow Command Injection vulnerability
Critical10.0Mar 30
MLFlow path traversal vulnerability
Critical9.6Mar 30
Arbitrary file write via tar traversal in mlflow
High8.1Mar 19
MLflow has a command injection in mlflow/sagemaker/__init__.py
High7.5Mar 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.