CVE-2026-69148
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.
Fraqueza
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.
Referências
- https://github.com/mlflow/mlflow/commit/4bb7474771c3be808cd9e129defef9305f2869be
- https://github.com/mlflow/mlflow/pull/24293
- https://github.com/mlflow/mlflow/releases/tag/v3.15.0
- https://github.com/mlflow/mlflow/security/advisories/GHSA-gqch-g4w5-7qcw
- https://github.com/mlflow/mlflow/security/advisories/GHSA-gqch-g4w5-7qcw
Encontre a falha antes de um atacante.
Entre com o GitHub e rode sua primeira auditoria em menos de um minuto. O plano gratuito não exige cartão de crédito.