Database/AI/ML frameworks & serving
MLflow: model version creation reads another user's run artifacts without READ permission
Impact
CreateModelVersion accepts a run_id or model_id whose validation only checks path containment, so an authenticated user can register a model version pointing at another user's artifact directory and then pull its contents through GET /model-versions/get-artifact without holding READ on that run. On a shared GPU cluster the MLflow artifact store is where checkpoints, training data samples, evaluation outputs and whatever secrets got logged along the way end up, and per-user permissions are the only thing separating teams inside one tracking server. This is cross-tenant read of model artifacts, not code execution — the record rates confidentiality high with limited integrity impact.
Who can reach it
Any authenticated MLflow user who can call CreateModelVersion against the tracking server. Requires knowing or guessing a target run_id or model_id; no elevated role needed.
What to do
Upgrade MLflow to 3.15.0 and restart the tracking server — a service restart, no GPU node maintenance. If the upgrade has to wait, treat artifact access on that server as effectively shared across all authenticated users and move anything sensitive out of the artifact store; the linked commit and PR show the added source ownership check.
References
Related entries
- MLflow AI Gateway: unvalidated api_base in gateway secrets turns the proxy endpoint into an authenticated SSRFCVE-2026-71211 · MLflow AI Gateway (gateway secret auth_config.api_base, raw_proxy endpoint)High
- Hugging Face tokenizers: crafted tokenizer.json aborts the process while loading a BPE modelCVE-2026-85670 · Hugging Face tokenizers (BpeBuilder::build, BPE merge loading)High
- Jupyter Server: Referer header is logged unscrubbed, leaking auth tokens into server logsCVE-2026-86049 · Jupyter Server (5xx request logging in jupyter_server/log.py)High
- n8n OpenAI Chat Model node: model-search path ignores credential domain limits and leaks the API keyCVE-2026-86082 · n8n OpenAI Chat Model node (LMChatOpenAi loadModels.ts model-search path)High
- vLLM: forged FLAC sample rate bypasses duration limit and crashes the API serverCVE-2026-90555 · vLLM (OpenAI-compatible transcription endpoint, audio header validation)High
- Hugging Face Transformers: path traversal in save_pretrained() writes files outside the save directoryCVE-2026-9856 · Hugging Face Transformers - save_pretrained() in PreTrainedTokenizerBase and ProcessorMixinHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.