Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-06-09
10 active CVEs reported via OSV.dev
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
MLFlow unsafe deserialization
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
MLflow Uncontrolled Resource Consumption vulnerability
MLflow authentication requirement bypass can allow a user to arbitrarily create an account
MLflow has Weak Password Requirements
MLflow has a Local File Read/Path Traversal in dbfs
mlflow Creates of Temporary File in Directory with Insecure Permissions
Path traversal in MLflow
Other Machine Learning projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for MLflow — without relying on volunteer maintainers.