
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15031 is a path traversal vulnerability in MLflow's pyfunc extraction process that allows arbitrary file writes via improper handling of tar archive entries. The flaw affects MLflow versions up to and including 3.10.1 (lfprojects/mlflow). It was disclosed on March 18, 2026, with the CVE assigned by Huntr AI. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). MLflow's pyfunc extraction process uses Python's tarfile.extractall without validating archive entry paths, allowing crafted tar.gz files containing .. sequences or absolute paths to write files outside the intended extraction directory. An unauthenticated attacker can supply a malicious artifact over the network — requiring no privileges or user interaction — to trigger the unsafe extraction. This is particularly dangerous in multi-tenant environments or pipelines that ingest untrusted model artifacts (Red Hat Bugzilla, Huntr Bounty).
Successful exploitation allows an unauthenticated attacker to overwrite arbitrary files on the host system, which can lead to remote code execution — for example, by overwriting application configuration files, SSH authorized keys, or Python module files loaded at runtime. Both confidentiality and integrity are rated High, as sensitive files can be read or replaced; availability impact is rated None in the primary CVSS scoring. The risk is elevated in multi-tenant MLflow deployments where multiple users share the same artifact processing infrastructure, enabling cross-tenant compromise (Red Hat Advisory, Red Hat Bugzilla).
No confirmed in-the-wild exploitation has been observed, and no functional public proof-of-concept exploit code is currently available — the Huntr bounty page referenced in NVD contains no exploit details. The EPSS score is approximately 0.03%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and is exploitable over the network, making it a high-priority patching target (Huntr Bounty, Red Hat Advisory).
../../etc/cron.d/backdoor, ../../home/user/.ssh/authorized_keys, or absolute paths like /etc/passwd) pointing to sensitive locations outside the intended extraction directory.tarfile.extractall on the malicious archive without path validation, writing attacker-controlled content to arbitrary filesystem locations./api/2.0/mlflow/artifacts/upload) containing tar.gz files from untrusted or external sources; unusual outbound connections from the MLflow server process after artifact extraction./etc/, /home/, /root/.ssh/, or application directories); unexpected files with names matching MLflow artifact entries in sensitive system paths.tarfile extraction errors or warnings referencing paths outside the artifact root.Upgrade MLflow to a version beyond 3.10.1 that includes a fix validating tar archive entry paths before extraction (patch tracked via Red Hat Bugzilla #2448912). As a workaround, restrict artifact upload capabilities to trusted, authenticated users only and isolate pyfunc extraction in sandboxed environments (e.g., containers with read-only mounts for sensitive paths). In multi-tenant deployments, implement strict controls on artifact sources and validate all archive entries for path traversal sequences (.. or absolute paths) before allowing extraction (Red Hat Bugzilla, Red Hat Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."