MLflowGHSA-hvc6-42vf-jhf8
mlflow Command Injection vulnerability
High8.8CVE-2023-6940 · Published Dec 19, 2023 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 2.9.2 | 2.9.2 |
Details and references
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-77
- Also known as
- BIT-mlflow-2023-6940, CVE-2023-6940, PYSEC-2026-1652
- nvd.nist.gov/vuln/detail/CVE-2023-6940
- github.com/mlflow/mlflow/pull/10676
- github.com/mlflow/mlflow/commit/5139b1087d686fa52e2b087e09da66aff86297b1
- github.com/mlflow/mlflow/commit/a98a341a7222f894b7735db575ad9311ecaba4e3
- github.com/mlflow/mlflow
- github.com/mlflow/mlflow/commits/v2.9.2
- huntr.com/bounties/c6f59480-ce47-4f78-a3dc-4bd8ca15029c
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 202023 | MLflow Server-Side Request Forgery (SSRF) CVE-2023-6974Critical9.8fixed in 2.9.2 | Critical9.8 | 2.9.2 |
| Dec 202023 | MLflow Path Traversal Vulnerability CVE-2023-6909High7.5fixed in 2.9.2 | High7.5 | 2.9.2 |
| Dec 202023 | MLFlow Path Traversal Vulnerability CVE-2023-6975Critical9.8fixed in 2.9.2 | Critical9.8 | 2.9.2 |
| Dec 202023 | MLflow Local File Disclosure Vulnerability CVE-2023-6977High7.5fixed in 2.9.2 | High7.5 | 2.9.2 |
| Dec 202023 | MLflow Path Traversal Vulnerability CVE-2023-6976High8.8fixed in 2.9.2 | High8.8 | 2.9.2 |
| Dec 152023 | Path traversal in MLflow CVE-2023-6831Critical10.0fixed in 2.9.2 | Critical10.0 | 2.9.2 |