Back to overview

CVE-2025-15379

CRITICAL Exploitation: PoC
10.0
CVSS 3.0
Description
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` file and directly interpolates them into a shell command without sanitization. This allows an attacker to supply a malicious model artifact and achieve arbitrary command execution on systems that deploy the model. The vulnerability affects versions 3.8.0 and is fixed in version 3.8.2.

Metadata

CVE ID
CVE-2025-15379
State
PUBLISHED
Assigner
@huntr_ai
Reserved
2025-12-30 21:24 UTC
Published
2026-03-30 07:16 UTC
Last updated
2026-03-31 13:50 UTC
Primary CWE
CWE-77
CWE-77 Improper Neutralization of Special Elements used in …
Vendor / Product
mlflow / mlflow/mlflow
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
mlflow mlflow/mlflow unspecified < 3.8.2
Weakness (CWE)
CWESourceDescription
CWE-77 cna CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview