GPU VulnDB

Database/AI/ML frameworks & serving

MLflow (model flavors): Deserialization RCE from a maliciously uploaded model (one of a family: 37052–37060)

CVE-2024-37052AI/ML frameworks & servingcurated

Impact

Deserialization RCE from a maliciously uploaded model (one of a family: 37052–37060)

Who can reach it

Customer-supplied model artifact loaded via mlflow.pyfunc.load_model

What to do

No format fix — every MLflow model flavor wraps pickle. Restrict who can register models and sandbox model-load workers

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.