PT-2026-29269 · Mlflow · Mlflow

Publicado

2026-03-31

·

Atualizado

2026-04-16

·

CVE-2026-0596

CVSS v3.1

9.6

Crítica

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mlflow/mlflow (affected versions not specified)
Description A command injection issue exists in mlflow/mlflow when serving a model with enable mlserver=True. The model uri is directly incorporated into a shell command executed using bash -c without sufficient sanitization. If the model uri includes shell metacharacters, such as $() or backticks, it enables command substitution and the execution of commands controlled by an attacker. This can lead to privilege escalation if a higher-privileged service serves models from a directory writable by lower-privileged users. The model uri is the vulnerable parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-MLFLOW-2026-0596
CVE-2026-0596
GHSA-RVHJ-8CHJ-8V3C

Produtos afetados

Mlflow