Skip to content
MLflowGHSA-xch3-2f9x-wh9f

MLflow has a command injection in mlflow/sagemaker/__init__.py

High7.5CVE-2025-14287 · Published Mar 16, 2026 · updated Sep 10, 2026

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct interpolation of user-supplied container image names into shell commands without proper sanitization, which are then executed using `os.system()`. This allows attackers to execute arbitrary commands by supplying malicious input through the `--container` parameter of the CLI. The issue affects environments where MLflow is used, including development setups, CI/CD pipelines, and cloud deployments.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.8.0rc03.8.0rc0
Details and references

More MLflow advisories

All MLflow
Advisory
MLflow: remote code execution
Critical9.1Apr 3
Mlflow: Command Injection when serving models with enable_mlserver=True
Critical9.6Mar 31
MLflow Command Injection vulnerability
Critical10.0Mar 30
MLFlow path traversal vulnerability
Critical9.6Mar 30
MLFlow allows Tracing + Assessments Access
High8.1Mar 27
Arbitrary file write via tar traversal in mlflow
High8.1Mar 19

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.