Known CVE
MLflow <= 3.9.0 - Arbitrary File Read
mlflow mlflow <= 3.9.0 contains a path traversal caused by bypassing source path validation via the mlflow.prompt.is_prompt tag in CreateModelVersion request, letting unauthenticated remote attackers read arbitrary files.
CVE-2026-2614
High2026CVSS 7.5CWE-22
cve2026 · mlflow · lfi · traversal
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website