VulnWatch VulnWatch
← Back to dashboard
Low osv · GHSA-pqcv-qw2r-r859

MLFlow improper input validation

Published Jun 4, 2024 CVSS 3.1
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run due to unfiltered input.

Affected AI Products

mlflow