{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mlflow/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lfai:mlflow:*:*:*:*:*:*:*:*","cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2023-6976"},{"cvss":7.5,"id":"CVE-2023-6977"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MLflow"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LF AI \u0026 Data Foundation"],"content_html":"\u003cp\u003eThe MLflow platform, managed by the LF AI \u0026amp; Data Foundation, is susceptible to multiple vulnerabilities that allow for remote code execution (RCE). These vulnerabilities, tracked under CVE-2023-6976, CVE-2023-6977, and CVE-2023-6978, arise from weaknesses in input validation and insecure deserialization processes within the software. These flaws enable an unauthenticated or low-privileged attacker to inject malicious payloads into the MLflow environment, leading to full system compromise. Given MLflow's common role in machine learning pipelines, a successful exploit could grant an attacker access to sensitive model data, training parameters, and the underlying infrastructure running the MLflow server or tracking components. Defenders should prioritize patching and assess exposure of MLflow instances to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to achieve arbitrary code execution on the server hosting MLflow. This level of access facilitates full environment compromise, potentially resulting in data exfiltration, tampering with machine learning model artifacts, and lateral movement within the network. These vulnerabilities represent a high risk for organizations leveraging MLflow for MLOps, particularly in cloud-native or research environments where the platform may be exposed to broader network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all MLflow installations to the latest version where these CVEs are addressed. As immediate mitigation, ensure that MLflow tracking servers are restricted to trusted internal networks and utilize robust authentication mechanisms. Review server logs for suspicious API requests or unexpected process execution patterns originating from the MLflow service account.\u003c/p\u003e\n","date_modified":"2026-09-24T13:58:02Z","date_published":"2026-09-24T13:58:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mlflow-code-execution/","summary":"Multiple vulnerabilities in MLflow, identified as CVE-2023-6976, CVE-2023-6977, and CVE-2023-6978, allow remote attackers to execute arbitrary code due to improper input validation and insecure deserialization.","title":"Multiple Vulnerabilities in MLflow Enabling Arbitrary Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-mlflow-code-execution/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2023-6683"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MLflow"],"_cs_severities":["low"],"_cs_tags":["vulnerability","mlflow","data-integrity","security-bypass"],"_cs_type":"advisory","_cs_vendors":["LF AI \u0026 Data"],"content_html":"\u003cp\u003eThe BSI has published a security advisory regarding a vulnerability in MLflow, an open-source platform for the machine learning lifecycle. The flaw allows a remote, unauthenticated attacker to bypass established security controls. By exploiting this vulnerability, an attacker can access sensitive data, disclose internal configuration or experiment metrics, and manipulate stored data within the MLflow instance. Because MLflow is frequently deployed in cloud-native environments to manage experiment tracking and model registry, this vulnerability poses a significant risk to the integrity and confidentiality of machine learning pipelines. Defenders should prioritize auditing access controls for MLflow instances and ensure that they are not exposed to the public internet without robust authentication mechanisms.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive machine learning assets, including model artifacts and training experiment metadata. This could facilitate the theft of proprietary models or the poisoning of training data. While the specific number of affected entities is not publicly disclosed, the widespread use of MLflow in data science and engineering sectors suggests a broad attack surface for organizations utilizing the platform in their production or R\u0026amp;D environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit MLflow deployment configurations to ensure that authentication and authorization features are strictly enforced.\u003c/li\u003e\n\u003cli\u003eRestrict access to the MLflow web interface and API endpoints to trusted internal networks or via VPNs.\u003c/li\u003e\n\u003cli\u003eReview access logs for anomalous behavior, such as unauthorized attempts to access /api/2.0/mlflow/ or registry-related endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized modification of experiment metadata or model artifacts.\u003c/li\u003e\n\u003cli\u003eApply the latest security updates provided by the MLflow development team to address CVE-2023-6683.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T13:10:26Z","date_published":"2026-08-20T13:10:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mlflow-security-bypass/","summary":"A vulnerability in the MLflow machine learning lifecycle platform allows unauthenticated remote attackers to bypass security controls, resulting in potential data disclosure or unauthorized data manipulation.","title":"Security Control Bypass in MLflow","url":"https://feed.craftedsignal.io/briefs/2026-08-mlflow-security-bypass/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-64849"},{"cvss":7.1,"id":"CVE-2026-69148"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MLflow Tracking Server","MLflow (\u003c 3.15.0)","MLflow"],"_cs_severities":["critical"],"_cs_tags":["ssrf","mlflow","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["MLflow"],"content_html":"\u003cp\u003eMLflow Tracking Server (v3.13.0 and earlier) contains an SSRF vulnerability (CVE-2026-64849) in its webhook delivery mechanism. While the application implements a validation function (\u003ccode\u003e_validate_webhook_url\u003c/code\u003e) intended to restrict connections to public IP addresses, the implementation fails to pin the resolved IP address, and the HTTP client follows redirects without re-validating the final destination. An unauthenticated attacker can create a webhook pointing to a controlled HTTPS endpoint that issues a 302 redirect to internal network resources, such as the AWS Instance Metadata Service (169.254.169.254) or loopback addresses. Because the synchronous \u003ccode\u003e/api/2.0/mlflow/webhooks/{id}/test\u003c/code\u003e endpoint reflects the response status and body back to the caller, this allows for unauthenticated full-read exfiltration of sensitive internal data or blind POST interactions with management interfaces on the local network.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing MLflow Tracking Server instance running with a default configuration (e.g., SQLite backend) lacking authentication plugins.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a malicious HTTPS-enabled server that returns a 302 HTTP redirect to an internal target (e.g., http://169.254.169.254/latest/meta-data/iam/security-credentials/).\u003c/li\u003e\n\u003cli\u003eAttacker submits a POST request to \u003ccode\u003e/api/2.0/mlflow/webhooks\u003c/code\u003e with the \u003ccode\u003eurl\u003c/code\u003e parameter pointing to the malicious attacker-controlled HTTPS endpoint.\u003c/li\u003e\n\u003cli\u003eMLflow validates the initial URL; since the attacker's endpoint is a valid public HTTPS URL, the \u003ccode\u003e_validate_webhook_url\u003c/code\u003e check passes.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the SSRF by sending a request to the \u003ccode\u003e/api/2.0/mlflow/webhooks/{id}/test\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe MLflow server executes the webhook, follows the 302 redirect to the internal target without re-validation, and fetches the sensitive internal resource.\u003c/li\u003e\n\u003cli\u003eThe server receives the internal response (e.g., cloud credentials) and reflects the full response body back to the attacker in the HTTP response of the \u003ccode\u003e/test\u003c/code\u003e request.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to exfiltrate sensitive cloud metadata (e.g., IAM role credentials), query internal-only services, or perform host scanning from the perspective of the MLflow server. Furthermore, by using 307 or 308 redirects, attackers can perform blind POST operations against internal management interfaces like Docker daemons or Spring Boot Actuator endpoints, potentially leading to remote code execution or service disruption within the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure your MLflow environment:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade MLflow to version 3.15.0 or later immediately to patch CVE-2026-64849.\u003c/li\u003e\n\u003cli\u003eEnable MLflow authentication plugins to ensure that the webhook API is not accessible to unauthenticated users.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate MLflow servers from sensitive cloud metadata endpoints (IMDSv1) and internal management interfaces.\u003c/li\u003e\n\u003cli\u003eDeploy the suggested webserver-level rules to detect potential SSRF attempts directed at common internal paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T22:27:32Z","date_published":"2026-08-18T00:46:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mlflow-ssrf/","summary":"MLflow Tracking Server versions prior to 3.15.0 are vulnerable to an unauthenticated full-read SSRF attack because the webhook delivery mechanism follows unvalidated HTTP redirects, allowing attackers to exfiltrate internal data or interact with local services.","title":"MLflow Tracking Server Unauthenticated Full-Read SSRF via Webhook Delivery","url":"https://feed.craftedsignal.io/briefs/2026-08-mlflow-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - MLflow","version":"https://jsonfeed.org/version/1.1"}