Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: lfprojects Clear
ID Title
CVE-2026-64849 KEV [KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
CVE-2026-52870 Vulnerability in mcp (CVE-2026-52870)
vulnerability in mcp (CVE-2026-52870). Confidential information can be exposed externally. Exploitable via ``TaskStore``. Mitigation: upgrade to `1.27.2` or later.
CVE-2026-8147 Vulnerability in mlflow (CVE-2026-8147)
vulnerability in mlflow (CVE-2026-8147). Confidential information can be exposed externally. Exploitable via ``_before_request``. Mitigation: upgrade to `3.13.0rc0` or later.
CVE-2026-13484 Vulnerability in lfprojects (CVE-2026-13484)
vulnerability in lfprojects (CVE-2026-13484). Risk of unauthorized operations or information disclosure.
CVE-2026-3198 Vulnerability in mlflow (CVE-2026-3198)
vulnerability in mlflow (CVE-2026-3198). Confidential information can be exposed externally. Exploitable via ``BEFORE_REQUEST_HANDLERS``. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-2651 Vulnerability in mlflow (CVE-2026-2651)
vulnerability in mlflow (CVE-2026-2651). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.1` or later.
CVE-2026-2734 Vulnerability in mlflow (CVE-2026-2734)
vulnerability in mlflow (CVE-2026-2734). Confidential information can be exposed externally. Exploitable via ``SearchModelVersions``. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-2611 Vulnerability in mlflow (CVE-2026-2611)
vulnerability in mlflow (CVE-2026-2611). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-2652 Vulnerability in mlflow (CVE-2026-2652)
vulnerability in mlflow (CVE-2026-2652). Data can be tampered with by attackers. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-2614 MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2026-2393 SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-2393)
SSRF in mlflow (CVE-2026-2393). Confidential information can be exposed externally. Exploitable via ``url``. Mitigation: upgrade to `3.9.0` or later.
CVE-2026-44430 SSRF (Server-Side Request Forgery) in github.com/modelcontextprotocol/registry (CVE-2026-44430)
SSRF in github.com/modelcontextprotocol/registry (CVE-2026-44430). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v0/auth/http`. Mitigation: upgrade to `1.7.7` or later.
CVE-2026-44429 Vulnerability in github.com/modelcontextprotocol/registry (CVE-2026-44429)
vulnerability in github.com/modelcontextprotocol/registry (CVE-2026-44429). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v0/auth/github-at`. Mitigation: upgrade to `1.7.7` or later.
CVE-2026-44428 SSRF (Server-Side Request Forgery) in github.com/modelcontextprotocol/registry (CVE-2026-44428)
SSRF in github.com/modelcontextprotocol/registry (CVE-2026-44428). Risk of unauthorized operations or information disclosure. Exploitable via ``c5c4b9e8890dd5754bee889b2f1417f4fe3b5ce5``. Mitigation: upgrade to `1.7.6` or later.
CVE-2026-0545 Vulnerability in mlflow (CVE-2026-0545)
vulnerability in mlflow (CVE-2026-0545). Confidential information can be exposed externally.
CVE-2026-34742 Vulnerability in github.com/modelcontextprotocol/go-sdk (CVE-2026-34742)
vulnerability in github.com/modelcontextprotocol/go-sdk (CVE-2026-34742). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
CVE-2026-0596 OS Command Injection in mlflow (CVE-2026-0596)
OS command injection in mlflow (CVE-2026-0596). Successful exploitation can lead to full system takeover. Exploitable via ``model_uri``. Mitigation: upgrade to `3.9.0` or later.
CVE-2025-15379 Command Injection in mlflow (CVE-2025-15379)
command injection in mlflow (CVE-2025-15379). Successful exploitation can lead to full system takeover. Exploitable via ``python_env.yaml``. Mitigation: upgrade to `3.8.1` or later.
CVE-2025-15036 Vulnerability in mlflow (CVE-2025-15036)
vulnerability in mlflow (CVE-2025-15036). Successful exploitation can lead to full system takeover. Exploitable via ``extract_archive_to_dir``. Mitigation: upgrade to `3.9.0rc0` or later.
CVE-2025-15381 Information Disclosure in lfprojects (CVE-2025-15381)
vulnerability in lfprojects (CVE-2025-15381). Data can be tampered with by attackers. Exploitable via ``NO_PERMISSIONS``.
CVE-2025-15031 Path Traversal in lfprojects (CVE-2025-15031)
path traversal in lfprojects (CVE-2025-15031). Confidential information can be exposed externally. Exploitable via ``tarfile.extractall``.
CVE-2025-14287 Code Injection in lfprojects (CVE-2025-14287)
code injection in lfprojects (CVE-2025-14287). Successful exploitation can lead to full system takeover.
CVE-2026-27896 Vulnerability in lfprojects (CVE-2026-27896)
vulnerability in lfprojects (CVE-2026-27896). Data can be tampered with by attackers.
CVE-2026-27623 Vulnerability in valkey (CVE-2026-27623)
vulnerability in valkey (CVE-2026-27623). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.3` or later.
CVE-2026-21863 Out-of-Bounds Read in valkey (CVE-2026-21863)
vulnerability in valkey (CVE-2026-21863). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.2.12, 8.0.7, 8.1.6, 9.0.2` or later.
CVE-2025-67733 Vulnerability in valkey (CVE-2025-67733)
vulnerability in valkey (CVE-2025-67733). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.2.12, 8.0.7, 8.1.6, 9.0.2` or later.
CVE-2026-25536 Vulnerability in lfprojects (CVE-2026-25536)
vulnerability in lfprojects (CVE-2026-25536). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →