Executive brief
MLflow is an open-source platform used by organizations to manage the machine learning lifecycle, including tracking experiments and deploying models. A security flaw in how it handles compressed archive files allows an attacker to write files to unauthorized locations on the server. This could lead to a total system takeover, data theft, or the ability to bypass security boundaries in shared cloud environments.
Technical details
A path traversal vulnerability (CWE-22/CWE-29) exists in the `extract_archive_to_dir` function within `mlflow/pyfunc/dbconnect_artifact_cache.py`. The root cause is a failure to validate tar member paths during the extraction of `tar.gz` files. An attacker who can provide or influence a malicious archive can use '..' sequences to escape the intended destination directory. This can be leveraged to overwrite sensitive system files, achieve arbitrary code execution, or escape sandboxes in multi-tenant or shared cluster environments. The issue is fixed in MLflow version 3.7.0 and later.
Affected products
- MLflow MLflow < 3.7.0
- Red Hat OpenShift AI (RHOAI) Affected
Timeline
- 2025-01-01: other: Initial Red Hat VEX release date
- 2026-03-30: disclosed: Public disclosure and NVD publication
- 2026-03-30: advisory: Red Hat security advisory published
References
- https://github.com/mlflow/mlflow/commit/3bf6d81ac4d38654c8ff012dbd0c3e9f17e7e346
- https://huntr.com/bounties/36c314cf-fd6e-4fb0-b9b0-1b47bcdf0eb0
- https://access.redhat.com/security/cve/CVE-2025-15036
- https://bugzilla.redhat.com/show_bug.cgi?id=2452925
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15036.json