
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15036 is a critical path traversal vulnerability in the MLflow machine learning platform, specifically in the extract_archive_to_dir function within mlflow/pyfunc/dbconnect_artifact_cache.py. The flaw arises from the absence of validation of tar member paths during archive extraction, allowing an attacker who controls a tar.gz file to write files outside the intended destination directory. It affects all MLflow versions before 3.9.0rc0 (the advisory description also references v3.7.0 as a boundary in some sources). The vulnerability was published on March 30, 2026, with a CVSS v3 base score of 9.6–10.0 (Critical), depending on the scoring source (GitHub Advisory, Feedly).
The root cause is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and CWE-29 (Path Traversal: ..\filename). The vulnerable extract_archive_to_dir function calls Python's tarfile.extractall() without first inspecting member paths for directory traversal sequences (e.g., ../), absolute paths (e.g., /tmp/evil), or symlink-based escapes. An attacker who can supply or influence the tar.gz artifact — for example, by placing a malicious model artifact in a shared MLflow artifact store — can craft entries with paths like ../pwned.txt or symlinks pointing outside the extraction directory. The fix, committed in mlflow@3bf6d81, introduces a check_tarfile_security() function that validates all member paths before extraction, rejecting absolute paths, escaped relative paths, and paths traversing symlinks (GitHub Commit, GitHub Advisory).
Successful exploitation allows an unauthenticated network attacker to overwrite arbitrary files on the host system, which can lead to remote code execution, privilege escalation, or full system compromise. In multi-tenant or shared cluster environments (e.g., Databricks clusters using DBConnect), an attacker could escape the sandbox directory and affect other tenants' data or system files. The impact spans all three security dimensions: high confidentiality loss (access to sensitive files), high integrity loss (arbitrary file overwrite), and high availability loss (potential disruption of system or service files) (GitHub Advisory, Red Hat Bugzilla).
No confirmed in-the-wild exploitation has been observed, and no functional public proof-of-concept exploit is currently available — the huntr.com bounty page referenced in the advisory was found to contain no meaningful exploit content (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.043–0.05%, placing it in the 14th percentile for near-term exploitation likelihood. Qualys has published a detection (ID 531088) for this vulnerability (Feedly).
../../../etc/cron.d/backdoor, an absolute path like /tmp/evil.sh, or a symlink pointing outside the extraction directory followed by a file traversing through it.extract_archive_to_dir().extract_archive_to_dir() on the malicious archive — for example, by triggering model loading or artifact retrieval via the MLflow API.tarfile.extractall() call writes files to attacker-controlled paths outside the intended destination directory, enabling overwrite of system files, cron jobs, SSH authorized keys, or other sensitive targets./tmp, /etc, home directories, or cron directories); newly created or modified files owned by the MLflow service account in sensitive system paths.tarfile extraction errors or MlflowException messages referencing path traversal (on patched systems detecting an attack attempt).curl/wget downloading secondary payloads, or unexpected cron job execution).Upgrade MLflow to version 3.9.0rc0 or later, which includes the check_tarfile_security() function that validates tar member paths before extraction (GitHub Advisory, GitHub Commit). As a workaround prior to patching, restrict access to the MLflow artifact store so that only trusted users can upload artifacts, and avoid exposing the DBConnect artifact cache extraction functionality to untrusted inputs. In multi-tenant environments, enforce strict access controls on artifact repositories and audit existing artifacts for suspicious tar.gz files with traversal paths (Red Hat Bugzilla).
The vulnerability received coverage from The Hacker Wire, which published an article specifically on the path traversal issue in MLflow's archive extraction (The Hacker Wire). Red Hat tracked the issue via Bugzilla and classified it as high severity (Red Hat Bugzilla). Social media discussion was noted on Mastodon and Bluesky, with security community accounts sharing the advisory shortly after publication. Qualys added a detection rule (ID 531088) for the vulnerability as part of their April 2026 application security detections release.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."