All CosmicBytez Labs articles tagged #mlflow, across news, security advisories, how-to guides, and projects.
CVE-2026-64849 (CVSS 9.3): Active SSRF exploitation in MLflow lets attackers steal AWS cloud credentials via redirect bypass. Added to CISA KEV.
Critical unauthenticated SSRF in MLflow's webhook system lets attackers redirect requests to steal AWS credentials. Upgrade to 3.15.0.
A CVSS 9.1 critical flaw in MLflow AI Gateway allows server-side environment variables in api_key fields to be resolved and exfiltrated to attacker-controlled…
A critical CVSS 9.6 vulnerability in MLflow 3.9.0 allows a remote attacker to exploit improper origin validation in the MLflow Assistant's /ajax-api...
A critical command injection vulnerability in mlflow/mlflow allows attackers to execute arbitrary shell commands by embedding metacharacters in the...
A critical path traversal vulnerability in MLflow's extract_archive_to_dir function allows attackers to write arbitrary files outside the intended...
A maximum-severity command injection vulnerability in MLflow's model serving container initialization allows attackers to execute arbitrary OS commands...