Low
osv
·
PYSEC-2026-1652
mlflow Command Injection vulnerability
Published Jul 7, 2026
CVSS 3.1
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
Affected AI Products
mlflow