Skip to content
MLflowGHSA-r23q-823p-vmf7

MLflow Command Injection vulnerability

Critical10.0CVE-2025-15379 · Published Mar 30, 2026 · updated Sep 10, 2026

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` file and directly interpolates them into a shell command without sanitization. This allows an attacker to supply a malicious model artifact and achieve arbitrary command execution on systems that deploy the model. The vulnerability affects versions 3.8.0 and is fixed in version 3.8.1.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.8.13.8.1
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow: cross-site scripting
Medium5.4Apr 7
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
Medium4.3Apr 7
MLflow: remote code execution
Critical9.1Apr 3
Mlflow: Command Injection when serving models with enable_mlserver=True
Critical9.6Mar 31
MLFlow path traversal vulnerability
Critical9.6Mar 30
MLFlow allows Tracing + Assessments Access
High8.1Mar 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.