CyberRota Analysis
AI-GeneratedMLflow's dspy flavor in versions 2.0 and above is vulnerable due to improper application of the MLFLOW_ALLOW_PICKLE_DESERIALIZATION security control, which only activates for model paths ending in .pkl. This oversight permits remote attackers to execute arbitrary code by exploiting crafted MLmodel artifacts. Organizations utilizing affected versions of MLflow should prioritize addressing this vulnerability to mitigate potential remote code execution risks.
Original NVD Description
MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.