Description
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2125 | Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run. |
Github GHSA |
GHSA-pqcv-qw2r-r859 | MLFlow improper input validation |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 03 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects mlflow |
|
| CPEs | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects mlflow |
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-08-02T03:43:50.824Z
Reserved: 2024-05-31T14:16:48.808Z
Link: CVE-2024-37061
Updated: 2024-08-02T03:43:50.824Z
Status : Analyzed
Published: 2024-06-04T12:15:12.703
Modified: 2025-02-03T14:48:37.123
Link: CVE-2024-37061
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA