Skip to content

Known CVE

MLflow <= 3.9.0 - Arbitrary File Read

mlflow mlflow <= 3.9.0 contains a path traversal caused by bypassing source path validation via the mlflow.prompt.is_prompt tag in CreateModelVersion request, letting unauthenticated remote attackers read arbitrary files.

CVE-2026-2614

High2026CVSS 7.5CWE-22

cve2026 · mlflow · lfi · traversal

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website