Executive brief
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
Affected products
- PyPI mlflow
Junglewise Threat Intelligence
CVE-2025-11201 · Severity: low · CVSS 3 · Published 2026-07-07
Technologies: mlflow (PyPI). Vendors: PyPI.
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability