Skip to content
MLflowGHSA-vqj2-4v8m-8vrq

Insecure Temporary File in mlflow

High8.2CVE-2022-0736 · Published Feb 24, 2022 · updated Feb 21, 2025

mlflow prior to 1.23.1 contains an insecure temporary file. The insecure function `tempfile.mktemp()` is deprecated and `mkstemp()` should be used instead.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 1.23.11.23.1
Details and references

More MLflow advisories

All MLflow
Advisory
mlflow Path Traversal vulnerability
Critical9.8May 17, 2023
mflow vulnerable to directory traversal
High7.5May 11, 2023
Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
CriticalMay 1, 2023
Relative path traversal in mlflow
High10.0Apr 28, 2023
Remote file existence check vulnerability in `mlflow server` and `mlflow ui` CLIs
Medium3.3Mar 24, 2023
mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
Critical9.8Mar 24, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.