VDB
Sign up
HIGH8.8

PYSEC-2026-1657

MLFlow improper input validation

Details

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run due to unfiltered input.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mlflow
Introduced in: 1.11.0

No fixed version published yet for mlflow (pip). Pin to a known-safe version or switch to an alternative.

References