GITHUBEXPLOIT 8.8 HIGH

Exploit for Deserialization of Untrusted Data in Lfprojects Mlflow_177FD468-7171-53E9-9C3E-AC561066B7E5

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

CVE-2024-37054 — MLflow pyfunc Deserialization RCE Severity: Critical Affected: MLflow 0.9.0 – 2.14.1 Type: Arbitrary code execution via Python pickle deserialization Description mlflow.pyfunc.loadmodel deserializes pythonmodel.pkl from the artifact...
Visit Original Source

Basic Information

ID 177FD468-7171-53E9-9C3E-AC561066B7E5
Published May 19, 2026 at 21:15
Modified May 19, 2026 at 21:18

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.