MLflow Vulnerabilities

pip MLOps

AI Threat Alert tracks 83 known vulnerabilities in MLflow, 19 rated critical — an AI/ML mlops in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
81
Risk Score
83
Total CVEs
19
Critical
pip
Ecosystem
Sep 8, 2026
Last CVE
36%
Patch Rate
75d
Avg Time to Patch
28,147 stars 6,371 forks 2,139 issues 691 dependents Last push Sep 27, 2026
View on GitHub
OpenSSF Scorecard 5.3/10

Known Vulnerabilities (83 total, page 3 of 4)

Severity CVE ID Summary CVSS Published
HIGH CVE-2024-37057 MLflow: RCE via malicious TensorFlow model deserialization 8.8 Jun 4, 2024 HIGH CVE-2024-37056 MLflow: RCE via LightGBM model deserialization 8.8 Jun 4, 2024 HIGH CVE-2024-37055 MLflow: RCE via pmdarima model deserialization 8.8 Jun 4, 2024 HIGH CVE-2024-37054 MLflow: deserialization RCE via malicious PyFunc model 8.8 Jun 4, 2024 HIGH CVE-2024-37053 MLflow: RCE via malicious scikit-learn model deserialization 8.8 Jun 4, 2024 HIGH CVE-2024-37052 MLflow: RCE via malicious scikit-learn model upload 8.8 Jun 4, 2024 MEDIUM CVE-2024-4263 MLflow: broken access control allows artifact deletion 5.4 May 16, 2024 HIGH CVE-2024-3848 MLflow: URL fragment bypass leaks SSH and cloud keys 7.5 May 16, 2024 CRITICAL CVE-2024-3573 MLflow: LFI via URI parsing allows arbitrary file read 9.3 Apr 16, 2024 HIGH CVE-2024-1594 MLflow: path traversal via URI fragment reads arbitrary files 7.5 Apr 16, 2024 HIGH CVE-2024-1593 MLflow: path traversal via ';' smuggling exposes files 7.5 Apr 16, 2024 HIGH CVE-2024-1560 MLflow: path traversal allows arbitrary directory deletion 8.1 Apr 16, 2024 HIGH CVE-2024-1558 MLflow: path traversal enables arbitrary file read 7.5 Apr 16, 2024 HIGH CVE-2024-1483 MLflow: path traversal exposes arbitrary server files 7.5 Apr 16, 2024 CRITICAL CVE-2024-27133 MLflow: XSS in recipe runner enables Jupyter RCE 9.6 Feb 23, 2024 CRITICAL CVE-2024-27132 MLflow: XSS in recipes enables client-side RCE 9.6 Feb 23, 2024 HIGH CVE-2023-6909 MLflow: path traversal exposes arbitrary files (no auth) 7.5 Dec 18, 2023 HIGH CVE-2023-6831 MLflow: path traversal allows arbitrary file write 8.1 Dec 15, 2023 HIGH CVE-2023-6753 MLflow: path traversal exposes arbitrary file read/write 8.8 Dec 13, 2023 HIGH CVE-2023-6709 MLflow: SSTI enables RCE in ML experiment tracking 8.8 Dec 12, 2023 MEDIUM CVE-2023-6568 MLflow: reflected XSS via Content-Type header injection 6.1 Dec 7, 2023 HIGH CVE-2023-43472 MLflow: unauth REST API leaks sensitive ML data 7.5 Dec 5, 2023 CRITICAL CVE-2023-6014 MLflow: auth bypass allows arbitrary account creation 9.8 Nov 16, 2023 CRITICAL CVE-2023-6018 MLflow: unauth file overwrite enables model poisoning 9.8 Nov 16, 2023 HIGH CVE-2023-6015 MLflow: unauthenticated arbitrary file write via PUT 7.5 Nov 16, 2023

Showing 51–75 of 83

Frequently asked questions

What is MLflow?

MLflow is an AI/ML mlops tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does MLflow have?

MLflow has 83 known CVEs, 19 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is MLflow distributed in?

MLflow is distributed via the pip ecosystem and categorized as mlops.

Where does the MLflow vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of MLflow?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor MLflow in your stack

Get instant alerts when new vulnerabilities affect MLflow. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring