Impact
A maliciously crafted model artifact can trigger the execution of arbitrary code on an end user's system when loaded by an MLflow project. This flaw allows an attacker to run code with the privileges of the user running the MLflow application, potentially compromising confidentiality, integrity, and availability of the host system.
Affected Systems
The MLflow platform (mlflow:mlflow) versions 0.0.1 and newer are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 8.6 marks this flaw as high severity, and the EPSS score is currently not available. It is not listed in the CISA KEV catalog. The likely attack vector involves an attacker delivering a malicious model artifact to an end user or an automated pipeline that loads untrusted artifacts. If executed, the attacker can control the target system with the same privileges as the MLflow process.
OpenCVE Enrichment