Skip to main content

Vendor archive

lfprojects CVEs

Beta · best-effort

113 CVEs tagged to vendor lfprojects18 Critical, 69 High, 21 Medium, 5 Low, 0 Unrated.

CVE-2025-65105

Published Dec 2, 2025

Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular…

CVSS 4.5 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2025-11201

Published Oct 29, 2025

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-11200

Published Oct 29, 2025

MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Aut…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-49844

Published Oct 3, 2025

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the gar…

CVSS 9.9 · Critical
evidence mentions
16
Buzz score
60.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1474

Published Mar 20, 2025

In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passw…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-1473

Published Mar 20, 2025

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new ac…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-0453

Published Mar 20, 2025

In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all r…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8859

Published Mar 20, 2025

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6838

Published Mar 20, 2025

In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a lim…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27134

Published Nov 25, 2024

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3099

Published Jun 6, 2024

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2928

Published Jun 6, 2024

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the ap…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0520

Published Jun 6, 2024

A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') with…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-37061

Published Jun 4, 2024

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end us…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37060

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37059

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37058

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37057

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37056

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37055

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary cod…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37054

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37053

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37052

Published Jun 4, 2024

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4263

Published May 16, 2024

A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifact…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 113 CVEsPage 3 of 5