216.73.217.22

CVE-2026-33865

· Published 07/04/2026 13:16 · Modified 07/04/2026 13:20

Labels: CVE-2026-33865 2026-04-07CVE-2026-33865CWE-79[email protected]

Essential information

Published
07/04/2026 13:16
Modified
07/04/2026 13:20
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows actions such as session hijacking or performing operations on behalf of the victim. This issue affects MLflow version through 3.10.1

NVD status

Status
Undergoing Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mlflow / mlflow cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:*

References