Loading HuntDB...

GHSA-qg8p-32gr-gh6x

GitHub Security Advisory

MLflow Local File Disclosure Vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

This vulnerability enables malicious users to read sensitive files on the server.

Affected Packages

PyPI mlflow
Affected versions: 0 (fixed in 2.9.2)

Related CVEs

Key Information

GHSA ID
GHSA-qg8p-32gr-gh6x
Published
December 20, 2023 6:30 AM
Last Modified
January 2, 2024 3:14 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
mlflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.