PT-2026-25547 · Databricks · Mlflow

CVE-2025-14287

·

Publicado

2025-12-08

·

Atualizado

2026-07-13

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mlflow versions prior to 3.7.0
Description A command injection issue exists due to the direct interpolation of user-supplied container image names into shell commands without proper sanitization. These commands are then executed using the os.system() function. This allows attackers to execute arbitrary commands by providing malicious input through the --container parameter of the CLI. The issue impacts environments where MLflow is used, including development setups, CI/CD pipelines, and cloud deployments. The vulnerable code is located in the mlflow/sagemaker/ init .py file at lines 161-167.
Recommendations Versions prior to 3.7.0 should be updated to version 3.7.0 or later.

Exploit

Correção

OS Command Injection

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-06596
BIT-MLFLOW-2025-14287
CVE-2025-14287
GHSA-XCH3-2F9X-WH9F
PYSEC-2026-2661

Produtos afetados

Mlflow