PT-2026-25547 · Databricks · Mlflow

Published

2025-12-08

·

Updated

2026-04-19

·

CVE-2025-14287

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mlflow versions prior to 3.7.0
Description A command injection issue exists due to the direct interpolation of user-supplied container image names into shell commands without proper sanitization. These commands are then executed using the os.system() function. This allows attackers to execute arbitrary commands by providing malicious input through the --container parameter of the CLI. The issue impacts environments where MLflow is used, including development setups, CI/CD pipelines, and cloud deployments. The vulnerable code is located in the mlflow/sagemaker/ init .py file at lines 161-167.
Recommendations Versions prior to 3.7.0 should be updated to version 3.7.0 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-06596
BIT-MLFLOW-2025-14287
CVE-2025-14287
GHSA-XCH3-2F9X-WH9F

Affected Products

Mlflow