Database/AI/ML frameworks & serving
MLflow: missing permission check on runs/log-inputs lets any user forge another run's lineage
Impact
LogInputs was never registered in BEFORE_REQUEST_HANDLERS, so the auth plugin performs no permission check on POST /api/2.0/mlflow/runs/log-inputs. Any authenticated user can name someone else's run_id and write attacker-chosen DatasetInput records into its dataset_inputs lineage without holding UPDATE on that run. On a shared cluster where MLflow is the multi-tenant record of which data trained which model, that makes provenance untrustworthy — for audit, for reproducing a run, and for model-governance sign-off. Any pipeline that reads dataset URIs back out of run lineage is then acting on strings another tenant supplied. Integrity only: no read access to other runs and no service disruption.
Who can reach it
Any user already authenticated to the MLflow tracking server with the auth plugin enabled, over the network. No permission on the target run is needed; run IDs are the only thing to guess, and they are widely visible within a workspace.
What to do
Upgrade to MLflow 3.15.0 and restart the tracking server; versions 3.13.0 up to 3.15.0 are affected. Patching stops new writes but does not clean up old ones, so review dataset_inputs on runs that matter for audit or reproducibility, particularly on any multi-tenant tracking server. No GPU node work.
References
Related entries
- vLLM: request-selected video decoder backend allocates GPU memory outside the KV-cache budgetCVE-2026-69147 · vLLM (MediaConnector video backend selection / GPU memory budgeting)Medium
- vLLM: unbounded prompt array in /v1/completions lets one request exhaust the engineCVE-2026-73559 · vLLM OpenAI-compatible server (/v1/completions prompt list)Medium
- vLLM: MiMo-V2-Omni processor bypasses media allowlists, enabling SSRF and local file readsCVE-2026-73560 · vLLM MiMoV2OmniMultiModalProcessor (media fetching in transformers_utils/processors/mimo_v2_omni.py)Medium
- OpenShift AI dashboard: unauthorized Secret read exposes the cluster NGC API key and NIM pull secretCVE-2026-86332 · Red Hat OpenShift AI odh-dashboard (GET /api/nim-serving/:nimResource)Medium
- Keras: malicious .keras/.h5 weights file reads arbitrary local files via HDF5 ExternalLinksCVE-2026-9335 · Keras (KerasFileEditor and keras.saving.load_weights HDF5 ExternalLink handling)Medium
- vLLM OpenAI-compatible server (chat_template / chat_template_kwargs): NOISY-NEIGHBOUR DENIAL OF SERVICE: one tenantNCVD-2025-018-vllm-openai-compatible-server-ch · vLLM OpenAI-compatible server (chat_template / chat_template_kwargs)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.