OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96775

HIGH · CVSS 8.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

MLflow's dspy flavor in versions 2.0 and above is vulnerable due to improper application of the MLFLOW_ALLOW_PICKLE_DESERIALIZATION security control, which only activates for model paths ending in .pkl. This oversight permits remote attackers to execute arbitrary code by exploiting crafted MLmodel artifacts. Organizations utilizing affected versions of MLflow should prioritize addressing this vulnerability to mitigate potential remote code execution risks.

CVE
CVE-2026-96775
Severity
HIGH
CVSS
8.8
EPSS
0.39%

Original NVD Description

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.