CVE-2026-0596
Published Mar 31, 2026A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via…
- evidence mentions
- 1
- Buzz score
- 11.9