CVE-2025-10279: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-10279 is a insecure temporary directory permissions vulnerability in MLflow that enables local attackers to exploit a race condition and achieve arbitrary code execution. In MLflow version 2.20.3, the temporary directory created for Python virtual environments is assigned world-writable permissions (0o777), allowing any local user with write access to /tmp to overwrite .py files within the virtual environment during its creation. The vulnerability was disclosed on February 2, 2026, and is resolved in MLflow version 3.4.0. It carries a CVSS v3.0 base score of 7.0 (High) (Red Hat CVE, Huntr Bounty).

Technical details

The root cause is classified as CWE-379 (Creation of Temporary File in Directory with Insecure Permissions). The vulnerable code in mlflow/utils/file_utils.py calls os.chmod(tmp_dir, 0o777) on a newly created temporary directory — originally intended to ensure Spark UDF accessibility — making it world-writable. An attacker with local access to the system can monitor /tmp for the creation of this directory and exploit the race condition window between directory creation and virtual environment population to overwrite .py files with malicious content. The fix, committed in GitHub commit 1d7c8d4, changes the permission to 0o750 (owner: rwx, group: r-x, others: none), eliminating write access for non-owners (Huntr Bounty, GitHub Commit).

Impact

Successful exploitation allows an attacker to inject malicious Python code into MLflow's virtual environment, resulting in arbitrary code execution with the privileges of the user running MLflow. This affects all three security pillars: confidentiality (access to data processed by MLflow), integrity (modification of ML pipeline code and outputs), and availability (potential disruption of MLflow services). The attack is local in nature but could enable privilege escalation or lateral movement within shared multi-user ML infrastructure environments (Huntr Bounty, Red Hat CVE).

Exploitability

A proof-of-concept exploit is publicly available on Huntr.com, though there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires low privileges (local user with /tmp write access) and high attack complexity due to the race condition timing requirement. The EPSS score is approximately 0.014% (0.000140), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Huntr Bounty, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target system running MLflow versions prior to 3.4.0 with local user access. Confirm that the /tmp directory is world-writable (default on most Linux systems).
  2. Monitor for temp directory creation: Use inotifywait or a polling loop to watch /tmp for the creation of a new directory by the MLflow process (e.g., inotifywait -m /tmp -e create -e isdir).
  3. Identify the target directory: When MLflow creates a temporary directory (via tempfile.mkdtemp()) and sets permissions to 0o777, the attacker detects the new directory path.
  4. Race condition exploitation: Immediately after the directory is created and before virtual environment population completes, overwrite or inject a malicious .py file (e.g., a site-packages module or startup script) within the virtual environment directory structure.
  5. Payload execution: When MLflow activates the virtual environment and imports the tampered Python file, the attacker's code executes with the privileges of the MLflow process, enabling reverse shell, credential theft, or further system compromise (Huntr Bounty, GitHub Commit).

Indicators of compromise

  • File System: Unexpected or recently modified .py files within MLflow temporary virtual environment directories under /tmp; directories under /tmp with 0o777 permissions owned by the MLflow service account.
  • Process: Unusual child processes spawned by the MLflow Python process (e.g., bash, curl, wget, nc, or other network tools); unexpected outbound network connections from the MLflow process.
  • Logs: MLflow logs showing virtual environment creation followed by unexpected import errors or module load failures; OS audit logs (auditd) recording file writes to /tmp/mlflow-* directories by non-MLflow users.
  • Network: Unexpected outbound connections from the MLflow server to external IPs shortly after virtual environment creation events.

Mitigation and workarounds

Upgrade MLflow to version 3.4.0 or later, which changes the temporary directory permissions from 0o777 to 0o750, eliminating world-write access (GitHub Commit). As a workaround for environments that cannot immediately upgrade, restrict write access to the /tmp directory to authorized users only, or configure MLflow to use a dedicated temporary directory with tightly controlled permissions. Additionally, consider running MLflow in isolated environments (containers, VMs) to limit the attack surface from local users (Huntr Bounty, Red Hat CVE).

Community reactions

Red Hat has published a CVE advisory tracking this vulnerability, indicating awareness among enterprise Linux distributors that package or integrate MLflow (Red Hat CVE). The vulnerability was reported through the Huntr bug bounty platform and credited to the security research community. Qualys has added detection signatures (IDs 5007351 and 530896) for this CVE, and it was included in Qualys's February 2026 application security detections summary (Qualys Notifications). Overall community reaction has been measured, consistent with the local-only, high-complexity nature of the vulnerability.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management