---
id: CVE-2024-1558
aliases:
  - GHSA-j62r-wxqq-f3gf
  - BIT-mlflow-2024-1558
  - PYSEC-2026-1653
title: mlflow vulnerable to Path Traversal
summary: mlflow vulnerable to Path Traversal
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: mlflow
product: mlflow
ecosystem: pip
affected:
  - mlflow < 2.12.1
patched:
  - mlflow 2.12.1
published: '2024-04-16'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-j62r-wxqq-f3gf'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1558'
  - url: 'https://github.com/mlflow/mlflow'
  - url: 'https://huntr.com/bounties/7f4dbcc5-b6b3-43dd-b310-e2d0556a8081'
tags:
  - osv
  - pip
epss: 0.00859
epssPercentile: 0.56733
ingestedAt: '2026-07-08T18:25:50.595Z'
---

## Overview

A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to improper validation of the `source` parameter. Attackers can exploit this vulnerability by crafting a `source` parameter that bypasses the `_validate_non_local_source_contains_relative_paths(source)` function's checks, allowing for arbitrary file read access on the server. The issue arises from the handling of unquoted URL characters and the subsequent misuse of the original `source` value for model version creation, leading to the exposure of sensitive files when interacting with the `/model-versions/get-artifact` handler.

## Affected packages

- `mlflow < 2.12.1`

## Remediation

Upgrade to a patched release:

- `mlflow 2.12.1`
