Loading HuntDB...

GHSA-pqcv-qw2r-r859

GitHub Security Advisory

MLFlow improper input validation

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run due to unfiltered input.

Affected Packages

PyPI mlflow
Affected versions: 1.11.0 (last affected: 2.13.1)

Related CVEs

Key Information

GHSA ID
GHSA-pqcv-qw2r-r859
Published
June 4, 2024 12:31 PM
Last Modified
June 5, 2024 1:25 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
mlflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 12, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.