Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4x5p-f36r-mxxr | mlflow Creates of Temporary File in Directory with Insecure Permissions |
Tue, 14 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfprojects
Lfprojects mlflow |
|
| CPEs | cpe:2.3:a:lfprojects:mlflow:*:-:*:*:*:*:*:* | |
| Vendors & Products |
Lfprojects
Lfprojects mlflow |
Wed, 04 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mlflow
Mlflow mlflow |
|
| Vendors & Products |
Mlflow
Mlflow mlflow |
Mon, 02 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtual environment, leading to arbitrary code execution. The issue is resolved in version 3.4.0. | |
| Title | Privilege Escalation in mlflow/mlflow | |
| Weaknesses | CWE-379 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2026-02-02T17:48:15.265Z
Reserved: 2025-09-11T15:38:58.426Z
Link: CVE-2025-10279
Updated: 2026-02-02T17:48:11.883Z
Status : Analyzed
Published: 2026-02-02T11:16:16.867
Modified: 2026-04-14T14:57:42.480
Link: CVE-2025-10279
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:44:52Z
Github GHSA