PyPI: mlflow
CVE-2026-2611
Safety vulnerability ID: SFTY-20260519-82468
Affected versions of the MLflow package are vulnerable to Improper Input Validation due to insufficient origin validation in the `/ajax-api` endpoints. The endpoints fail to properly enforce origin checks, allowing cross-origin requests from malicious webpages to interact with the MLflow Assistant. An attacker can exploit this by hosting a malicious webpage that issues requests to the victim's local MLflow instance, potentially modifying configurations and executing arbitrary commands through the Claude Code sub-agent.
Overview
MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
Advisory
mlflow – Origin Validation Error
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260519-82468/CVE-2026-2611
- https://nvd.nist.gov/vuln/detail/CVE-2026-2611
- https://github.com/mlflow/mlflow/commit/8f9c8a53af90842944101eb8b7d60706822c81bc
- https://huntr.com/bounties/8462addd-b464-4a84-b6a2-5529604e6e5a
- https://github.com/advisories/GHSA-67c5-x5mf-rppq
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
