Database/AI/ML frameworks & serving
MLflow (tracking server): Path traversal (`\..\filename`)
Impact
Path traversal (\..\filename) → arbitrary file read
Who can reach it
Unauthenticated network to the MLflow tracking server
What to do
Upgrade to 2.2.1+; MLflow has no auth by default
Fleet impact
How widespread
Common - MLflow is the default experiment/model registry alongside GPU training clusters
Cost to remediate
daemon-restart - upgrade the tracking server; the pain is credential rotation, since leaked SSH keys and cloud creds must be assumed compromised
Why it hits the whole fleet
Unauthenticated LFI via the Model Versions API reads any file the server can read - SSH keys, cloud credentials - and one tracking server usually fronts every team's models and artifact buckets
References
Related entries
- Ray (dashboard /static/ file handler): Path traversal under the dashboard's /static/ route lets an unauthenticatedCVE-2023-6020 · Ray (dashboard /static/ file handler)Critical
- MLflow (LFI via URI parsing): Local file inclusion — read arbitrary filesCVE-2024-3573 · MLflow (LFI via URI parsing)Critical
- Milvus: Unauthenticated attacker exploits the server directlyCVE-2025-64513 · MilvusCritical
- Obot: quickstart container listens on 0.0.0.0 with auth off, granting anyone admin and the host Docker socketCVE-2026-101065 · Obot AI agent/MCP platform (documented Docker quickstart)Critical
- OpenShift AI guardrails-detectors: unauthenticated blind SSRF and file read via crafted XSDCVE-2026-15378 · Red Hat OpenShift AI guardrails-detectors (XSD schema parsing)Critical
- Jupyter Server: notebook HTML rendered without CSP sandbox gives stored XSS and kernel RCECVE-2026-44727 · Jupyter Server nbconvert HTTP handlers (Content-Security-Policy sandbox directive)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.