Junglewise Threat Intelligence

CVE-2025-15036: MLflow path traversal in extract_archive_to_dir

CVE-2025-15036 · Severity: critical · CVSS 10 · Published 2026-03-30

Technologies: Red Hat OpenShift AI (RHOAI), Mlflow, mlflow (PyPI). Vendors: Red Hat, MLflow, PyPI.

Executive brief

MLflow is an open-source platform used by organizations to manage the machine learning lifecycle, including tracking experiments and deploying models. A security flaw in how it handles compressed archive files allows an attacker to write files to unauthorized locations on the server. This could lead to a total system takeover, data theft, or the ability to bypass security boundaries in shared cloud environments.

Technical details

A path traversal vulnerability (CWE-22/CWE-29) exists in the `extract_archive_to_dir` function within `mlflow/pyfunc/dbconnect_artifact_cache.py`. The root cause is a failure to validate tar member paths during the extraction of `tar.gz` files. An attacker who can provide or influence a malicious archive can use '..' sequences to escape the intended destination directory. This can be leveraged to overwrite sensitive system files, achieve arbitrary code execution, or escape sandboxes in multi-tenant or shared cluster environments. The issue is fixed in MLflow version 3.7.0 and later.

Affected products

  • MLflow MLflow < 3.7.0
  • Red Hat OpenShift AI (RHOAI) Affected

Timeline

  • 2025-01-01: other: Initial Red Hat VEX release date
  • 2026-03-30: disclosed: Public disclosure and NVD publication
  • 2026-03-30: advisory: Red Hat security advisory published

References

Related threats