VulnWatch VulnWatch
← Back to dashboard
Low osv ยท PYSEC-2024-240

PYSEC-2024-240

Published Feb 23, 2024 CVSS 3.1
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.

Affected AI Products

mlflow