Skip to content
MLflowGHSA-hh8p-p8mp-gqhm

MLFlow Path Traversal Vulnerability

Critical9.8CVE-2023-6975 · Published Dec 20, 2023 · updated Jun 29, 2026

A malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.9.22.9.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-29
Also known as
BIT-mlflow-2023-6975, CVE-2023-6975, PYSEC-2026-422

More MLflow advisories

All MLflow
Advisory
MLflow Server-Side Request Forgery (SSRF)
Critical9.8Dec 20, 2023
MLflow Path Traversal Vulnerability
High7.5Dec 20, 2023
MLflow Local File Disclosure Vulnerability
High7.5Dec 20, 2023
MLflow Path Traversal Vulnerability
High8.8Dec 20, 2023
mlflow Command Injection vulnerability
High8.8Dec 19, 2023
Path traversal in MLflow
Critical10.0Dec 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.