Impact
MLRun versions up to and including 1.11.0 contain a server‑side request forgery flaw in the WebhookNotification handler. An authenticated user can inject a malicious webhook notification during a run; when the run finishes, the API server automatically executes the notification and makes arbitrary HTTP requests to any address reachable from within the cluster. By directing these requests to internal services, the Kubernetes API, or cloud metadata endpoints, an attacker can exfiltrate data or gain information about the environment.
Affected Systems
The vulnerability affects the MLRun platform provided by mlrun:mlrun. It is present in all releases up to version 1.11.0 and is resolved in later releases. Users running earlier releases in any cloud or on‑premises Kubernetes cluster are potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires that the user is already authenticated to the MLRun API; however, once that condition is satisfied, no additional privileges are needed to initiate the SSRF.
OpenCVE Enrichment