Skip to content
MLflowGHSA-rfqq-wq6w-72jm

MLflow has a Local File Read/Path Traversal bypass

High7.5CVE-2024-3848 · Published May 16, 2024 · updated Apr 8, 2025

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
>= 2.9.2, < 2.12.12.12.1
Details and references

More MLflow advisories

All MLflow
Advisory
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLFlow unsafe deserialization
High8.8Jun 4, 2024
MLflow allows low privilege users to delete any artifact
Medium5.4May 16, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.