Skip to content
MLflowGHSA-j46q-5pxx-8vmw

Local File Inclusion in mlflow

High7.5CVE-2024-2928 · Published Jun 6, 2024 · updated Apr 8, 2025

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system, including sensitive files like '/etc/passwd'. The vulnerability is a bypass to a previous patch that only addressed similar manipulation within the URI's query string, highlighting the need for comprehensive validation of all parts of a URI to prevent LFI attacks.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.11.32.11.3
Details and references

More MLflow advisories

All MLflow
Advisory
Undefined Behavior in mlflow
Medium5.4Jun 6, 2024
Remote code execution in mlflow
Critical10.0Jun 6, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow improper input validation
High8.8Jun 4, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.