PT-2026-30820 · Databricks · Mlflow
Sławomir Zakrzewski
·
Published
2026-04-07
·
Updated
2026-04-21
·
CVE-2026-33865
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MLflow versions through 3.10.1
Description
MLflow is susceptible to Stored Cross-Site Scripting (XSS) due to unsafe parsing of YAML-based MLmodel artifacts within its web interface. An authenticated attacker can upload a malicious MLmodel file that executes when another user views the artifact in the UI, potentially leading to session hijacking or unauthorized actions performed on behalf of the victim. Additionally, an authorization bypass exists in the AJAX endpoint used for downloading saved model artifacts. Missing access-control validation allows a user without appropriate permissions to directly query this endpoint and retrieve model artifacts they are not authorized to access.
Recommendations
Update MLflow to a version later than 3.10.1.
Exploit
Fix
Missing Authorization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mlflow