GHSA-46r5-x6jq-v8g6MediumCVSS 4.3

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint

Published
April 7, 2026
Last Modified
June 6, 2026

🔗 CVE IDs covered (1)

📋 Description

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access.

This issue affects MLflow version through 3.10.1

🎯 Affected products1

  • pip/mlflow:<= 3.10.1

🔗 References (7)