CVE-2026-4137 Details
Description
In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with group-writable permissions (0o770). These insecure permissions allow local attackers to tamper with model artifacts, such as cloudpickle-serialized Python objects, and achieve arbitrary code execution when the tampered artifacts are deserialized via `cloudpickle.load()`. This vulnerability is particularly critical in environments with shared NFS mounts, such as Databricks, where NFS is enabled by default. The issue is a continuation of the vulnerability class addressed in CVE-2025-10279, which was only partially fixed.
A vulnerability in MLflow in versions prior to 3.11.0 allows local attackers to execute arbitrary code by exploiting insecure temporary directory permissions. The 'get_or_create_nfs_tmp_dir()' function in 'mlflow/utils/file_utils.py' creates directories with world-writable permissions, while the '_create_model_downloading_tmp_dir()' function in 'mlflow/pyfunc/__init__.py' creates directories that are group-writable. This issue is critical in environments with shared NFS mounts, such as Databricks, where NFS is enabled by default. The vulnerability arises because MLflow downloads model artifacts, including cloudpickle-serialized Python objects, into these insecure directories and deserializes them without integrity verification, allowing for code execution via tampered artifacts.
Users can update to MLflow version 3.11.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://huntr.com/bounties/648dc30b-76c7-4433-86b8-f43d926fd8d6 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/mlflow/mlflow/commit/1dcbb0c2fbd1f446c328830e601ca13a28219b8a | [email protected] | Patch |
| https://huntr.com/bounties/648dc30b-76c7-4433-86b8-f43d926fd8d6 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-378 | Creation of Temporary File With Insecure Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects mlflow | < 3.11.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 19, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | New CVE Received | [email protected] |