Database/AI/ML frameworks & serving
MLflow (serving container init): Command injection in `_install_model_dependencies`
CVSS 9.8CVE-2025-15379AI/ML frameworks & servingcurated
Impact
Command injection in _install_model_dependencies
Who can reach it
Customer-supplied model requirements consumed when the provider builds a serving container
What to do
Provider-owned in managed serving: the tenant's requirements file executes shell in the build
References
Related entries
- Keras (`Model.load_model`): Arbitrary code execution from a crafted `.keras` archive even with `safe_mode=True`CVE-2025-1550 · Keras (`Model.load_model`)Critical
- LlamaIndex (vector store integrations): SQL injection across multiple vector store integrationsCVE-2025-1793 · LlamaIndex (vector store integrations)Critical
- picklescan (model scanner): Scanner fails to detect malicious pickles when ZIP flag bits are flippedCVE-2025-1945 · picklescan (model scanner)Critical
- NVIDIA Triton: Stack buffer overflowCVE-2025-23310 · NVIDIA TritonCritical
- NVIDIA Triton: Stack overflow via crafted requestCVE-2025-23311 · NVIDIA TritonCritical
- NVIDIA Triton Inference Server (Python backend): Attacker-controlled input in the Python backendCVE-2025-23316 · NVIDIA Triton Inference Server (Python backend)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.