Skip to content
MLflowGHSA-qg8p-32gr-gh6x

MLflow Local File Disclosure Vulnerability

High7.5CVE-2023-6977 · Published Dec 20, 2023 · updated Jul 7, 2026

This vulnerability enables malicious users to read sensitive files on the server.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.9.22.9.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-29
Also known as
BIT-mlflow-2023-6977, CVE-2023-6977, PYSEC-2026-1659

More MLflow advisories

All MLflow
Advisory
MLflow Server-Side Request Forgery (SSRF)
Critical9.8Dec 20, 2023
MLflow Path Traversal Vulnerability
High7.5Dec 20, 2023
MLFlow Path Traversal Vulnerability
Critical9.8Dec 20, 2023
MLflow Path Traversal Vulnerability
High8.8Dec 20, 2023
mlflow Command Injection vulnerability
High8.8Dec 19, 2023
Path traversal in MLflow
Critical10.0Dec 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.