Loading HuntDB...

GHSA-j46q-5pxx-8vmw

GitHub Security Advisory

Local File Inclusion in mlflow

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system, including sensitive files like '/etc/passwd'. The vulnerability is a bypass to a previous patch that only addressed similar manipulation within the URI's query string, highlighting the need for comprehensive validation of all parts of a URI to prevent LFI attacks.

Affected Packages

PyPI mlflow
Affected versions: 0 (fixed in 2.11.3)

Related CVEs

Key Information

GHSA ID
GHSA-j46q-5pxx-8vmw
Published
June 6, 2024 9:30 PM
Last Modified
April 8, 2025 10:01 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
mlflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 24, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.