Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | MLflow > 3.15.0 contains an information disclosure vulnerability caused by improper validation of webhook URLs allowing attackers to reach internal or cloud metadata services and obtain response details, exploit requires unauthenticated access to the webhook test endpoint. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-64849.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-69148 | 7.1 HIGH | MLflow: CreateModelVersion source validation does not check READ permission on referenced |
| CVE-2026-69146 | 6.5 MEDIUM | MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth |
No comments yet