---
id: CVE-2026-2611
aliases:
  - GHSA-67c5-x5mf-rppq
title: >-
  MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints
  Enables Browser-Mediated Local Command Execution
summary: >-
  MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints
  Enables Browser-Mediated Local Command Execution
severity: critical
cvss: 9.6
cwe:
  - CWE-346
  - CWE-940
vendor: mlflow
product: mlflow
ecosystem: pip
affected:
  - mlflow = 3.9.0
patched:
  - mlflow 3.10.0
published: '2026-05-19'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T21:33:12Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-67c5-x5mf-rppq'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2611'
  - url: >-
      https://github.com/mlflow/mlflow/commit/8f9c8a53af90842944101eb8b7d60706822c81bc
  - url: 'https://huntr.com/bounties/8462addd-b464-4a84-b6a2-5529604e6e5a'
  - url: 'https://access.redhat.com/security/cve/CVE-2026-2611'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2479797'
  - url: 'https://github.com/advisories/GHSA-67c5-x5mf-rppq'
  - url: 'https://github.com/mlflow/mlflow'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2026-418.yaml
  - url: 'https://pypi.org/project/mlflow'
tags:
  - ghsa
  - pip
epss: 0.00414
epssPercentile: 0.33491
ingestedAt: '2026-10-05T21:34:25.117Z'
---

## Overview

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via the Claude Code sub-agent. This issue is resolved in version 3.10.0.

## Affected packages

- `mlflow = 3.9.0`

## Remediation

Upgrade to a patched release:

- `mlflow 3.10.0`
