PyPI: mlflow

CVE-2024-27132

Safety vulnerability ID: SFTY-20240223-25505

Safety legacy ID: pyup.io-68487

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.

Created at: May 22, 2026Updated at: May 22, 2026

Overview

Cross-site Scripting in MLFlow

Advisory

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.

Affected Package

Affecting mlflow package, versions
<2.10.0

Also affects

---

How to Fix

Upgrade
mlflow
to
2.10.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more