PT-2025-26607 · Mlflow · Mlflow

Oxqndo

·

Published

2025-06-23

·

Updated

2025-09-25

·

CVE-2025-52967

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: MLflow versions prior to 3.1.0
Description: The issue is related to the gateway proxy handler in MLflow, which lacks gateway path validation. This could potentially lead to exploitation.
Recommendations: For versions prior to 3.1.0, update to version 3.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the gateway proxy handler until a patch is available.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-09012
BIT-MLFLOW-2025-52967
CVE-2025-52967
GHSA-WXJ7-3FX5-PP9M
PYSEC-2025-52

Affected Products

Mlflow