PyPI: mlflow

CVE-2026-33865

Safety vulnerability ID: SFTY-20260407-39486

Safety legacy ID: pyup.io-93804

Affected versions of the mlflow package are vulnerable to Stored Cross-Site Scripting due to unsafe parsing of YAML-based MLmodel artifacts when rendered in the web interface. The web UI processes attacker-supplied fields from uploaded ML model files without adequate output sanitization, allowing embedded payloads to be emitted into the rendered artifact view and executed in the browser of any user who opens the artifact. An authenticated attacker who uploads a malicious ML model file can trigger script execution in the context of a victim's session, enabling session hijacking or actions performed on the victim's behalf.

Created at: Apr 24, 2026Updated at: Apr 24, 2026

Overview

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface

Advisory

Affected versions of the mlflow package are vulnerable to Stored Cross-Site Scripting due to unsafe parsing of YAML-based MLmodel artifacts when rendered in the web interface. The web UI processes attacker-supplied fields from uploaded ML model files without adequate output sanitization, allowing embedded payloads to be emitted into the rendered artifact view and executed in the browser of any user who opens the artifact. An authenticated attacker who uploads a malicious ML model file can trigger script execution in the context of a victim's session, enabling session hijacking or actions performed on the victim's behalf.

Affected Package

Affecting mlflow package, versions
<=3.10.1

Also affects

---

How to Fix

Upgrade
mlflow
to
3.11.0rc0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more