Junglewise Threat Intelligence

CVE-2025-15031: MLflow path traversal in pyfunc extraction

CVE-2025-15031 · Severity: critical · CVSS 9.1 · Published 2026-03-18

Technologies: Red Hat OpenShift AI (RHOAI), LF Projects Mlflow. Vendors: Red Hat, PyPI.

Executive brief

MLflow is an open-source platform used by organizations to manage the machine learning lifecycle, including model tracking and deployment. A security flaw in how it handles model files allows an attacker to write malicious files to any location on the server's disk. This could lead to a complete system takeover, data theft, or disruption of machine learning operations, especially in environments where multiple teams share the same infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in MLflow's pyfunc extraction process due to the insecure use of 'tarfile.extractall' without proper path validation. An attacker can provide a specially crafted tar.gz archive containing entries with '..' sequences or absolute paths to escape the intended extraction directory. This allows for arbitrary file overwrites on the host system. In multi-tenant environments or when ingesting untrusted artifacts, this can be leveraged to achieve remote code execution. The vulnerability affects MLflow versions up to 3.10.1 and has been identified in downstream products like Red Hat OpenShift AI.

Affected products

  • LF Projects MLflow up to and including 3.10.1
  • Red Hat OpenShift AI (RHOAI) unspecified

Timeline

  • 2026-03-18: disclosed: Vulnerability reported via huntr.dev
  • 2026-03-18: advisory: Initial CVE publication

References

Related threats