Skip to content
MLflowGHSA-wqxf-447m-6f5f

Information exposure in MLflow

High7.5CVE-2023-43472 · Published Dec 5, 2023 · updated Jul 7, 2026

An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 2.9.02.9.0
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow Path Traversal Vulnerability
High8.8Dec 20, 2023
mlflow Command Injection vulnerability
High8.8Dec 19, 2023
Path traversal in MLflow
Critical10.0Dec 15, 2023
Path traversal in MLflow
High8.8Dec 13, 2023
Jinja2 template injection in mlflow
High8.8Dec 12, 2023
Cross-site Scripting (XSS) in MLflow
Medium6.5Dec 7, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.