PyPI: mlflow

CVE-2026-2611

Safety vulnerability ID: SFTY-20260519-82468

Affected versions of the MLflow package are vulnerable to Improper Input Validation due to insufficient origin validation in the `/ajax-api` endpoints. The endpoints fail to properly enforce origin checks, allowing cross-origin requests from malicious webpages to interact with the MLflow Assistant. An attacker can exploit this by hosting a malicious webpage that issues requests to the victim's local MLflow instance, potentially modifying configurations and executing arbitrary commands through the Claude Code sub-agent.

Created at: Jul 15, 2026Updated at: Jul 15, 2026

Overview

MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution

Advisory

mlflow – Origin Validation Error

Affected Package

Affecting mlflow package, versions
== 3.9.0

Also affects

---

How to Fix

Upgrade
mlflow
to
3.10.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more