Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-1177 mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIsCVE-2023-2780 mlflow Path Traversal vulnerabilityCVE-2023-3765 MLflow Path Traversal vulnerabilityCVE-2023-6014 MLflow authentication requirement bypass can allow a user to arbitrarily create an accountCVE-2023-6015 MLflow allowed arbitrary files to be PUT onto the serverCVE-2023-6018 Remote Code Execution due to Full Controled File Write in mlflowCVE-2023-6831 Path traversal in MLflowCVE-2023-6974 MLflow Server-Side Request Forgery (SSRF)CVE-2023-6975 MLFlow Path Traversal VulnerabilityCVE-2024-0520 Remote code execution in mlflowCVE-2024-27132 Cross-site Scripting in MLFlowCVE-2024-27133 MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code ExecutionCVE-2024-3573 mlflow vulnerable to Path TraversalCVE-2025-15036 mlflow: mlflow: Path traversal vulnerability allows arbitrary file overwrite and privilege escalationCVE-2025-15379 mlflow: MLflow: Arbitrary command execution via command injection in model serving container initialization.CVE-2026-0596 Mlflow: Command Injection when serving models with enable_mlserver=TrueCVE-2026-2635 mlflow: MLflow Use of Default Password Authentication Bypass VulnerabilityCVE-2026-2651 github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload accessCVE-2026-4035 python-mlflow: MLflow: Sensitive credential exfiltration via environment variable resolution in AI Gateway secretsGHSA-83fm-w79m-64r5 Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIsCVE-2022-45907 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line c ...CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...CVE-2023-1177 mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIsCVE-2023-2780 mlflow Path Traversal vulnerabilityCVE-2023-3765 MLflow Path Traversal vulnerabilityYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-253 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.PYSEC-2023-29 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.PYSEC-2023-308 Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.PYSEC-2023-68 Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.PYSEC-2023-69 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.PYSEC-2024-239 A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.hPYSEC-2024-240 Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.
The vulnerability stemsPYSEC-2024-241 Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerabilPYSEC-2024-243 mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_locPYSEC-2026-2220 A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce rPYSEC-2026-2222 A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environmePYSEC-2026-415 MLflow authentication requirement bypass can allow a user to arbitrarily create an accountPYSEC-2026-416 MLflow Server-Side Request Forgery (SSRF)PYSEC-2026-417 Remote Code Execution due to Full Controled File Write in mlflowPYSEC-2026-419 mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorizationPYSEC-2026-420 MLflow allowed arbitrary files to be PUT onto the serverPYSEC-2026-421 MLflow Use of Default Password Authentication Bypass VulnerabilityPYSEC-2026-422 MLFlow Path Traversal VulnerabilityPYSEC-2026-423 MLflow Command Injection vulnerabilityPYSEC-2026-424 Mlflow: Command Injection when serving models with enable_mlserver=TruePYSEC-2026-425 MLFlow path traversal vulnerabilityGHSA-83fm-w79m-64r5 Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIsPYSEC-2020-107 ** DISPUTED ** scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system callPYSEC-2022-43015 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.PYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.