Vulnerability record · CVE-2023-1177 · published 24 March 2023
CVE-2023-1177: MLflow path traversal via backslash filename before 2.2.1
Lfprojects · Mlflow
MLflow versions prior to 2.2.1 are vulnerable to a path traversal flaw (CWE-22/CWE-29) where a crafted '\..\filename' input escapes the intended directory. The issue is remotely reachable with no authentication or user interaction, and a public exploit reference exists, making it a serious risk for exposed MLflow instances.
Description
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and a public exploit reference plus very high EPSS make this an urgent patch.
What it is
MLflow versions prior to 2.2.1 are vulnerable to a path traversal flaw (CWE-22/CWE-29) where a crafted '\..\filename' input escapes the intended directory. The issue is remotely reachable with no authentication or user interaction, and a public exploit reference exists, making it a serious risk for exposed MLflow instances.
Impact
An attacker can read and write files outside the intended directory, potentially leading to data exposure or code execution depending on what files are reachable. The CVSS 3.1 score of 9.8 reflects high confidentiality, integrity, and availability impact.
Attack surface
Reached over the network via HTTP with no authentication (PR:N) and no user interaction (UI:N) per the CVSS vector. Any network-exposed MLflow service running a version before 2.2.1 is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is 0.6968 (99.3rd percentile), indicating high predicted exploitation activity. A public exploit reference is tagged in the advisory, so working exploit code is likely available.
What to do
- Upgrade MLflow to 2.2.1 or later, applying the patch commit referenced in the advisory.
- Restrict network access to MLflow tracking and model registry endpoints to trusted networks or authenticated proxies.
- Run MLflow with least-privilege filesystem permissions so traversal cannot reach sensitive files.
- Monitor for and block path traversal patterns such as '\..\' in request paths at the reverse proxy or WAF.
Detection
- Inspect MLflow access logs for request paths containing '\..\' or encoded traversal sequences.
- Alert on file access outside the MLflow artifact or tracking directories by the MLflow process.
- Use file integrity monitoring on directories reachable by the MLflow service to catch unexpected reads or writes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mlflow/mlflow/pull/7891/commits/7162a50c654792c21f3e4a160eb1a0e6a34f6e6e | Patch |
| https://huntr.dev/bounties/1fe8f21a-c438-4cba-9add-e8a5dab94e28 | ExploitPatchThird Party Advisory |
| https://github.com/mlflow/mlflow/pull/7891/commits/7162a50c654792c21f3e4a160eb1a0e6a34f6e6e | Patch |
| https://huntr.dev/bounties/1fe8f21a-c438-4cba-9add-e8a5dab94e28 | ExploitPatchThird Party Advisory |
Track CVE-2023-1177 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-1177), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.