
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10279 is a insecure temporary directory permissions vulnerability in MLflow that enables local attackers to exploit a race condition and achieve arbitrary code execution. In MLflow version 2.20.3, the temporary directory created for Python virtual environments is assigned world-writable permissions (0o777), allowing any local user with write access to /tmp to overwrite .py files within the virtual environment during its creation. The vulnerability was disclosed on February 2, 2026, and is resolved in MLflow version 3.4.0. It carries a CVSS v3.0 base score of 7.0 (High) (Red Hat CVE, Huntr Bounty).
The root cause is classified as CWE-379 (Creation of Temporary File in Directory with Insecure Permissions). The vulnerable code in mlflow/utils/file_utils.py calls os.chmod(tmp_dir, 0o777) on a newly created temporary directory — originally intended to ensure Spark UDF accessibility — making it world-writable. An attacker with local access to the system can monitor /tmp for the creation of this directory and exploit the race condition window between directory creation and virtual environment population to overwrite .py files with malicious content. The fix, committed in GitHub commit 1d7c8d4, changes the permission to 0o750 (owner: rwx, group: r-x, others: none), eliminating write access for non-owners (Huntr Bounty, GitHub Commit).
Successful exploitation allows an attacker to inject malicious Python code into MLflow's virtual environment, resulting in arbitrary code execution with the privileges of the user running MLflow. This affects all three security pillars: confidentiality (access to data processed by MLflow), integrity (modification of ML pipeline code and outputs), and availability (potential disruption of MLflow services). The attack is local in nature but could enable privilege escalation or lateral movement within shared multi-user ML infrastructure environments (Huntr Bounty, Red Hat CVE).
A proof-of-concept exploit is publicly available on Huntr.com, though there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires low privileges (local user with /tmp write access) and high attack complexity due to the race condition timing requirement. The EPSS score is approximately 0.014% (0.000140), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Huntr Bounty, Feedly).
/tmp directory is world-writable (default on most Linux systems).inotifywait or a polling loop to watch /tmp for the creation of a new directory by the MLflow process (e.g., inotifywait -m /tmp -e create -e isdir).tempfile.mkdtemp()) and sets permissions to 0o777, the attacker detects the new directory path..py file (e.g., a site-packages module or startup script) within the virtual environment directory structure..py files within MLflow temporary virtual environment directories under /tmp; directories under /tmp with 0o777 permissions owned by the MLflow service account.bash, curl, wget, nc, or other network tools); unexpected outbound network connections from the MLflow process.auditd) recording file writes to /tmp/mlflow-* directories by non-MLflow users.Upgrade MLflow to version 3.4.0 or later, which changes the temporary directory permissions from 0o777 to 0o750, eliminating world-write access (GitHub Commit). As a workaround for environments that cannot immediately upgrade, restrict write access to the /tmp directory to authorized users only, or configure MLflow to use a dedicated temporary directory with tightly controlled permissions. Additionally, consider running MLflow in isolated environments (containers, VMs) to limit the attack surface from local users (Huntr Bounty, Red Hat CVE).
Red Hat has published a CVE advisory tracking this vulnerability, indicating awareness among enterprise Linux distributors that package or integrate MLflow (Red Hat CVE). The vulnerability was reported through the Huntr bug bounty platform and credited to the security research community. Qualys has added detection signatures (IDs 5007351 and 530896) for this CVE, and it was included in Qualys's February 2026 application security detections summary (Qualys Notifications). Overall community reaction has been measured, consistent with the local-only, high-complexity nature of the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."