mlflow
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mlflowpage 1 of 1
- CVE-2026-69146MEDIUMCVSS 6.5EG 6.5✓ Fixed in 3.15.02026-08-17
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any aut…
- CVE-2026-69148HIGHCVSS 7.1EG 7.1✓ Fixed in 3.15.02026-08-17
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in m…
Check whether mlflow is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mlflow CVEs against the assets you own.
Start Free Scan →