Executive brief
MLflow is an open-source platform for managing the machine learning lifecycle. A security flaw in the MLflow Assistant feature allows a malicious website to send unauthorized commands to the MLflow application running on a user's local computer. If exploited, an attacker could gain full control over the victim's local machine and execute arbitrary commands, potentially leading to data theft or complete system compromise.
Technical details
An improper origin validation vulnerability (CWE-346) exists in the /ajax-api endpoints of the MLflow Assistant feature in version 3.9.0. The application fails to properly restrict cross-origin requests, allowing a malicious webpage to bypass loopback-only restrictions. By sending crafted requests through a victim's browser, a remote attacker can modify the Assistant's configuration to enable full access. This configuration change allows the attacker to leverage the integrated Claude Code sub-agent to execute arbitrary shell commands on the host system. The vulnerability is exploited via a network attack vector but requires user interaction (visiting a malicious site). The issue is resolved in version 3.10.0 by implementing stricter CORS blocking for AJAX paths.
Affected products
- MLflow mlflow 3.9.0
Timeline
- 2026-02-16: patched: Fix committed to repository
- 2026-05-19: disclosed: CVE-2026-2611 published
- 2026-05-19: advisory: GitHub Advisory GHSA-67c5-x5mf-rppq published