Database/AI/ML frameworks & serving
MLflow (LFI via URI parsing): Local file inclusion — read arbitrary files
CVSS 9.3CVE-2024-3573AI/ML frameworks & servingcurated
Impact
Local file inclusion — read arbitrary files
Who can reach it
Unauthenticated network to the tracking server
What to do
Upgrade; one of ~15 traversal variants, each a bypass of the last
References
Related entries
- Milvus: Unauthenticated attacker exploits the server directlyCVE-2025-64513 · MilvusCritical
- Obot: quickstart container listens on 0.0.0.0 with auth off, granting anyone admin and the host Docker socketCVE-2026-101065 · Obot AI agent/MCP platform (documented Docker quickstart)Critical
- OpenShift AI guardrails-detectors: unauthenticated blind SSRF and file read via crafted XSDCVE-2026-15378 · Red Hat OpenShift AI guardrails-detectors (XSD schema parsing)Critical
- Jupyter Server: notebook HTML rendered without CSP sandbox gives stored XSS and kernel RCECVE-2026-44727 · Jupyter Server nbconvert HTTP handlers (Content-Security-Policy sandbox directive)Critical
- OpenMed: unauthenticated model_name routes to a trust_remote_code loader and executes attacker codeCVE-2026-47117 · OpenMed privacy-filter model loader (model_name dispatcher, trust_remote_code=True path)Critical
- MLflow: unauthenticated webhook test follows redirects, turning the tracking server into an SSRF proxyCVE-2026-64849 · MLflow tracking server (webhook test endpoint, /api/2.0/mlflow/webhooks/{id}/test)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.