CVE-2025-15031: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15031 is a path traversal vulnerability in MLflow's pyfunc extraction process that allows arbitrary file writes via improper handling of tar archive entries. The flaw affects MLflow versions up to and including 3.10.1 (lfprojects/mlflow). It was disclosed on March 18, 2026, with the CVE assigned by Huntr AI. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). MLflow's pyfunc extraction process uses Python's tarfile.extractall without validating archive entry paths, allowing crafted tar.gz files containing .. sequences or absolute paths to write files outside the intended extraction directory. An unauthenticated attacker can supply a malicious artifact over the network — requiring no privileges or user interaction — to trigger the unsafe extraction. This is particularly dangerous in multi-tenant environments or pipelines that ingest untrusted model artifacts (Red Hat Bugzilla, Huntr Bounty).

Impact

Successful exploitation allows an unauthenticated attacker to overwrite arbitrary files on the host system, which can lead to remote code execution — for example, by overwriting application configuration files, SSH authorized keys, or Python module files loaded at runtime. Both confidentiality and integrity are rated High, as sensitive files can be read or replaced; availability impact is rated None in the primary CVSS scoring. The risk is elevated in multi-tenant MLflow deployments where multiple users share the same artifact processing infrastructure, enabling cross-tenant compromise (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional public proof-of-concept exploit code is currently available — the Huntr bounty page referenced in NVD contains no exploit details. The EPSS score is approximately 0.03%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and is exploitable over the network, making it a high-priority patching target (Huntr Bounty, Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify MLflow deployments (version ≤ 3.10.1) exposed to the network, particularly those accepting artifact uploads from external or untrusted sources, using service discovery tools or by probing the MLflow REST API.
  2. Craft malicious tar.gz: Create a tar.gz archive containing one or more entries with path traversal sequences (e.g., ../../etc/cron.d/backdoor, ../../home/user/.ssh/authorized_keys, or absolute paths like /etc/passwd) pointing to sensitive locations outside the intended extraction directory.
  3. Upload malicious artifact: Submit the crafted tar.gz as a pyfunc model artifact to the target MLflow instance via the artifact upload API or model registry, exploiting the lack of authentication requirements where applicable.
  4. Trigger extraction: Initiate a pyfunc model load or serving operation that causes MLflow to call tarfile.extractall on the malicious archive without path validation, writing attacker-controlled content to arbitrary filesystem locations.
  5. Achieve code execution: Depending on the overwritten file (e.g., a cron job, SSH key, or Python module), gain remote code execution or persistent access to the host system (Red Hat Bugzilla, Huntr Bounty).

Indicators of compromise

  • Network: Unexpected artifact upload requests to MLflow REST API endpoints (e.g., /api/2.0/mlflow/artifacts/upload) containing tar.gz files from untrusted or external sources; unusual outbound connections from the MLflow server process after artifact extraction.
  • File System: Newly created or modified files outside the MLflow artifact storage directory (e.g., changes to /etc/, /home/, /root/.ssh/, or application directories); unexpected files with names matching MLflow artifact entries in sensitive system paths.
  • Logs: MLflow server logs showing artifact extraction operations followed by unexpected file system activity; Python tarfile extraction errors or warnings referencing paths outside the artifact root.
  • Process: Unexpected child processes spawned by the MLflow server process (e.g., shells, cron daemons, or network utilities) shortly after artifact ingestion events.

Mitigation and workarounds

Upgrade MLflow to a version beyond 3.10.1 that includes a fix validating tar archive entry paths before extraction (patch tracked via Red Hat Bugzilla #2448912). As a workaround, restrict artifact upload capabilities to trusted, authenticated users only and isolate pyfunc extraction in sandboxed environments (e.g., containers with read-only mounts for sensitive paths). In multi-tenant deployments, implement strict controls on artifact sources and validate all archive entries for path traversal sequences (.. or absolute paths) before allowing extraction (Red Hat Bugzilla, Red Hat Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management