Executive brief
MLflow, a popular platform for managing machine learning lifecycles, contains a security flaw that allows unauthorized users to read sensitive files from the server. By sending a specially crafted request to create a model version, an attacker can trick the system into exposing internal configuration files, credentials, or other private data. This could lead to a full breach of confidentiality for the affected machine learning environment.
Technical details
A path traversal vulnerability exists in the `_create_model_version()` handler within `mlflow/server/handlers.py`. The vulnerability is triggered when a `CreateModelVersion` request includes the specific tag `mlflow.prompt.is_prompt`, which causes the server to bypass standard source path validation. An attacker can provide an arbitrary local filesystem path as the model version source. Subsequently, the `get_model_version_artifact_handler()` function serves files from this path without re-verifying the prompt status or path legitimacy. This allows unauthenticated remote attackers to retrieve any file accessible to the MLflow server process. The issue is resolved in version 3.10.0.
Affected products
- mlflow mlflow <= 3.9.0
Timeline
- 2026-05-11: advisory: NVD publication date
- 2026-05-11: disclosed: Initial disclosure via huntr.dev
- 2026-05-11: patched: Fix committed to MLflow repository