MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
High severity
GitHub Reviewed
Published
Feb 21, 2026
to the GitHub Advisory Database
•
Updated Mar 17, 2026
Description
Published by the National Vulnerability Database
Feb 20, 2026
Published to the GitHub Advisory Database
Feb 21, 2026
Reviewed
Mar 17, 2026
Last updated
Mar 17, 2026
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of artifact file paths. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account.
References