CVE-2024-37058High· 8.8▾ TwilightMLFlow unsafe deserialization
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.
mlflow >= 2.5.0, <= 2.14.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-37055High· 8.8MLFlow unsafe deserialization
CVE-2024-37059High· 8.8MLFlow unsafe deserialization
CVE-2024-37061High· 8.8MLFlow improper input validation
CVE-2024-37057High· 8.8MLFlow unsafe deserialization
CVE-2024-37054High· 8.8MLFlow unsafe deserialization
CVE-2024-37060High· 8.8MLFlow unsafe deserialization