Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-96804High· 8.8MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.
CVE-2026-96775High· 8.8MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.
CVE-2026-79721High· 8.6Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
GHSA-gqvg-gmmx-x4hmHigh· 8.8MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
CVE-2026-69146Medium· 6.5MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…
CVE-2026-69148High· 7.1MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…
CVE-2026-71211High· 7.1PoCMLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy…
CVE-2026-8147High· 8.1MLflow: trace API endpoints lack proper authorization validators
CVE-2026-10803Low· 3.6MLflow: Deterministic sampling in dataset digest enables predictable collisions
CVE-2026-4035Critical· 9.1MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
CVE-2026-3198Medium· 6.5MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
CVE-2026-2651Critical· 9.0MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
CVE-2026-2734Medium· 6.5MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
CVE-2026-4137High· 7.0MLFlow Creates a Temporary File With Insecure Permissions
CVE-2026-2652High· 8.6PoCMLflow: unauthenticated access to certain FastAPI routes
CVE-2026-2393High· 7.1MLflow Has a Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-33866Medium· 4.3MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
CVE-2025-15036Critical· 9.6MLFlow path traversal vulnerability
CVE-2025-15381High· 8.1MLFlow allows Tracing + Assessments Access
CVE-2025-15031High· 8.1Arbitrary file write via tar traversal in mlflow
CVE-2025-14287High· 7.5MLflow has a command injection in mlflow/sagemaker/__init__.py
CVE-2026-2033High· 8.10dayMLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
CVE-2026-2635High· 7.30day⚖ disputedMLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…
CVE-2025-10279High· 7.0mlflow Creates of Temporary File in Directory with Insecure Permissions
CVE-2025-14279High· 8.1MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.