MLflow是MLflow开源的一个简化机器学习开发的平台,包括跟踪实验、将代码打包成可重复的运行以及共享和部署模型。 MLflow 3.9.0及之前版本存在路径遍历漏洞,该漏洞源于_create_model_version处理程序在CreateModelVersion请求包含mlflow.prompt.is_prompt标签时绕过源路径验证,允许未经身份验证的远程攻击者从服务器文件系统读取任意文件,导致机密性完全泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mlflow | mlflow/mlflow | unspecified< 3.10.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mlflow | mlflow/mlflow | unspecified ~ 3.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | mlflow mlflow <= 3.9.0 contains a path traversal caused by bypassing source path validation via the mlflow.prompt.is_prompt tag in CreateModelVersion request, letting unauthenticated remote attackers read arbitrary files. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-2614.yaml | POC Details |
VULNERABLE: arbitrary file /flag.txt read via model-version get-artifact endpoint; exfiltrated token: PROOF_7e3b4e19afd4f3e8
No comments yet