---
id: CVE-2024-1560
aliases:
  - GHSA-5mvj-wmgj-7q8c
  - BIT-mlflow-2024-1560
  - PYSEC-2026-1641
title: mlflow vulnerable to Path Traversal
summary: mlflow vulnerable to Path Traversal
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
vendor: mlflow
product: mlflow
ecosystem: pip
affected:
  - mlflow <= 2.9.2
published: '2024-04-16'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-5mvj-wmgj-7q8c'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1560'
  - url: 'https://github.com/mlflow/mlflow'
  - url: 'https://huntr.com/bounties/4a34259c-3c8f-4872-b178-f27fbc876b98'
tags:
  - osv
  - pip
epss: 0.00856
epssPercentile: 0.56587
ingestedAt: '2026-07-08T18:25:46.037Z'
---

## Overview

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding process in the `_delete_artifact_mlflow_artifacts` handler and `local_file_uri_to_path` function, allowing for the deletion of arbitrary directories on the server's filesystem. This vulnerability is due to an extra unquote operation in the `delete_artifacts` function of `local_artifact_repo.py`, which fails to properly sanitize user-supplied paths. The issue is present up to version 2.9.2, despite attempts to fix a similar issue in CVE-2023-6831.

## Affected packages

- `mlflow <= 2.9.2`

## Remediation

Refer to the advisory for the patched release.
