Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.33% | — | Lfprojects Mlflow | 27/3/2026 | 5/10/2026 | In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should… | |
| Modificada | Crítica (9.1) | 0.85% | — | Lfprojects Mlflow | 18/3/2026 | 15/7/2026 | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables crafted tar.gz files containing `..` or absolute paths to escape the intended extraction directory. This… | |
| Modificada | Alta (8.8) | 1.5% | — | Lfprojects Mlflow | 16/3/2026 | 15/7/2026 | A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct interpolation of user-supplied container image names into shell commands without proper sanitization, which are then… | |
| Aplazada | Alta (7.3) | 1.2% | — | Lfprojects MlflowAI | 20/2/2026 | 15/7/2026 | MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The file contains… | |
| Aplazada | Alta (7.3) | 1.7% | — | Lfprojects MlflowAI | 20/2/2026 | 15/7/2026 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (7) | 0.24% | — | Lfprojects Mlflow | 2/2/2026 | 17/6/2026 | In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtual environment,… | |
| Analizada | Alta (8.1) | 0.21% | — | Lfprojects Mlflow | 12/1/2026 | 17/6/2026 | MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against REST endpoints. An attacker can query,… | |
| Analizada | Crítica (9.8) | 26% | 💥 PoC | Lfprojects Mlflow | 29/10/2025 | 17/6/2026 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.8) | 1.4% | — | Lfprojects Mlflow | 29/10/2025 | 17/6/2026 | MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from… | |
| Aplazada | Media (5.8) | 0.44% | — | Lfprojects MlflowAI | 23/6/2025 | 17/6/2026 | gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation. | |
| Analizada | Media (5.5) | 0.36% | — | Lfprojects Mlflow | 20/3/2025 | 17/6/2026 | In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The… | |
| Analizada | Alta (7.1) | 0.22% | — | Lfprojects Mlflow | 20/3/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user. | |
| Modificada | Alta (7.5) | 11% | — | Lfprojects Mlflow | 20/3/2025 | 17/6/2026 | In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other… | |
| Analizada | Alta (7.5) | 2.7% | 💥 Exploit | Lfprojects Mlflow | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and… | |
| Analizada | Media (5.3) | 0.65% | — | Lfprojects Mlflow | 20/3/2025 | 17/6/2026 | In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. This can cause the MLflow UI panel to become unresponsive, leading to a potential denial of service.… | |
| Analizada | Alta (7) | 0.12% | — | Lfprojects Mlflow | 25/11/2024 | 17/6/2026 | Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called. | |
| Modificada | Media (5.4) | 0.44% | — | Lfprojects Mlflow | 6/6/2024 | 17/6/2026 | A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (DoS) as an authenticated user might not be able to use the intended model, as it will open a different model each time. Additionally, an… | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Lfprojects Mlflow | 6/6/2024 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by… | |
| Modificada | Alta (8.8) | 2.4% | 💥 PoC | Lfprojects Mlflow | 6/6/2024 | 17/6/2026 | A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a source URL with an HTTP scheme, the filename… | |
| Analizada | Alta (8.8) | 0.88% | — | Lfprojects Mlflow | 4/6/2024 | 17/6/2026 | Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run. | |
| Analizada | Alta (8.8) | 0.78% | — | Lfprojects Mlflow | 4/6/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run. | |
| Analizada | Alta (8.8) | 0.62% | — | Lfprojects Mlflow | 4/6/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with. | |
| Analizada | Alta (8.8) | 0.62% | — | Lfprojects Mlflow | 4/6/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with. | |
| Analizada | Alta (8.8) | 0.62% | — | Lfprojects Mlflow | 4/6/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with. | |
| Analizada | Alta (8.8) | 0.62% | — | Lfprojects Mlflow | 4/6/2024 | 17/6/2026 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with. |