Skip to content
MLflowGHSA-q2r8-vmq7-fpx2

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

High8.1CVE-2026-2033 · Published Feb 21, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.8.0rc03.8.0rc0
Details and references

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of artifact file paths. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account.

CVSS 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2026-2033, PYSEC-2026-2658

More MLflow advisories

All MLflow
DateAdvisory
Feb 21MLflow Use of Default Password Authentication Bypass Vulnerability
CVE-2026-2635Critical9.8fixed in 3.8.0rc0
Feb 2mlflow Creates of Temporary File in Directory with Insecure Permissions
CVE-2025-10279High7.0fixed in 3.4.0rc0
Mar 16MLflow has a command injection in mlflow/sagemaker/__init__.py
CVE-2025-14287High7.5fixed in 3.8.0rc0
Mar 19Arbitrary file write via tar traversal in mlflow
CVE-2025-15031High8.1fixed in 3.9.0rc0
Mar 27MLFlow allows Tracing + Assessments Access
CVE-2025-15381High8.1no fix yet
Mar 30MLFlow path traversal vulnerability
CVE-2025-15036Critical9.6fixed in 3.9.0rc0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.