CyberRota Analysis
AI-GeneratedAuthenticated users of MLflow versions prior to 3.15.0 can exploit a flaw in the CreateModelVersion function to access another user's artifact directory, potentially exposing sensitive files without proper permissions. This vulnerability poses a significant risk to data confidentiality and integrity within AI and machine learning projects. Organizations using MLflow should prioritize upgrading to version 3.15.0 or later to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.