CVE-2025-15036: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-15036 is a critical path traversal vulnerability in the MLflow machine learning platform, specifically in the extract_archive_to_dir function within mlflow/pyfunc/dbconnect_artifact_cache.py. The flaw arises from the absence of validation of tar member paths during archive extraction, allowing an attacker who controls a tar.gz file to write files outside the intended destination directory. It affects all MLflow versions before 3.9.0rc0 (the advisory description also references v3.7.0 as a boundary in some sources). The vulnerability was published on March 30, 2026, with a CVSS v3 base score of 9.6–10.0 (Critical), depending on the scoring source (GitHub Advisory, Feedly).

Technical details

The root cause is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and CWE-29 (Path Traversal: ..\filename). The vulnerable extract_archive_to_dir function calls Python's tarfile.extractall() without first inspecting member paths for directory traversal sequences (e.g., ../), absolute paths (e.g., /tmp/evil), or symlink-based escapes. An attacker who can supply or influence the tar.gz artifact — for example, by placing a malicious model artifact in a shared MLflow artifact store — can craft entries with paths like ../pwned.txt or symlinks pointing outside the extraction directory. The fix, committed in mlflow@3bf6d81, introduces a check_tarfile_security() function that validates all member paths before extraction, rejecting absolute paths, escaped relative paths, and paths traversing symlinks (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated network attacker to overwrite arbitrary files on the host system, which can lead to remote code execution, privilege escalation, or full system compromise. In multi-tenant or shared cluster environments (e.g., Databricks clusters using DBConnect), an attacker could escape the sandbox directory and affect other tenants' data or system files. The impact spans all three security dimensions: high confidentiality loss (access to sensitive files), high integrity loss (arbitrary file overwrite), and high availability loss (potential disruption of system or service files) (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional public proof-of-concept exploit is currently available — the huntr.com bounty page referenced in the advisory was found to contain no meaningful exploit content (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.043–0.05%, placing it in the 14th percentile for near-term exploitation likelihood. Qualys has published a detection (ID 531088) for this vulnerability (Feedly).

Exploitation steps

  1. Reconnaissance: Identify MLflow deployments running versions prior to 3.9.0, particularly those using the DBConnect artifact cache feature in shared or multi-tenant cluster environments (e.g., Databricks).
  2. Craft malicious tar.gz: Create a tar.gz archive containing one or more entries with path traversal sequences, such as ../../../etc/cron.d/backdoor, an absolute path like /tmp/evil.sh, or a symlink pointing outside the extraction directory followed by a file traversing through it.
  3. Deliver the archive: Place the malicious tar.gz as a model artifact in an MLflow artifact store accessible to the target system, or otherwise supply it to a code path that invokes extract_archive_to_dir().
  4. Trigger extraction: Cause the MLflow server or worker to invoke extract_archive_to_dir() on the malicious archive — for example, by triggering model loading or artifact retrieval via the MLflow API.
  5. Achieve arbitrary file write: The unvalidated tarfile.extractall() call writes files to attacker-controlled paths outside the intended destination directory, enabling overwrite of system files, cron jobs, SSH authorized keys, or other sensitive targets.
  6. Escalate privileges / execute code: Leverage the overwritten file (e.g., a cron job or startup script) to execute arbitrary commands with the privileges of the MLflow service account, potentially gaining full system access (GitHub Commit, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected files appearing outside MLflow's designated artifact or cache directories (e.g., in /tmp, /etc, home directories, or cron directories); newly created or modified files owned by the MLflow service account in sensitive system paths.
  • Logs: MLflow server or worker logs showing artifact extraction operations followed by unexpected file system activity; Python tarfile extraction errors or MlflowException messages referencing path traversal (on patched systems detecting an attack attempt).
  • Process: Unusual processes spawned by the MLflow service account (e.g., reverse shells, curl/wget downloading secondary payloads, or unexpected cron job execution).
  • Network: Outbound connections from the MLflow server to unknown external IPs shortly after artifact extraction events, potentially indicating post-exploitation activity.

Mitigation and workarounds

Upgrade MLflow to version 3.9.0rc0 or later, which includes the check_tarfile_security() function that validates tar member paths before extraction (GitHub Advisory, GitHub Commit). As a workaround prior to patching, restrict access to the MLflow artifact store so that only trusted users can upload artifacts, and avoid exposing the DBConnect artifact cache extraction functionality to untrusted inputs. In multi-tenant environments, enforce strict access controls on artifact repositories and audit existing artifacts for suspicious tar.gz files with traversal paths (Red Hat Bugzilla).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article specifically on the path traversal issue in MLflow's archive extraction (The Hacker Wire). Red Hat tracked the issue via Bugzilla and classified it as high severity (Red Hat Bugzilla). Social media discussion was noted on Mastodon and Bluesky, with security community accounts sharing the advisory shortly after publication. Qualys added a detection rule (ID 531088) for the vulnerability as part of their April 2026 application security detections release.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management