← Vulnerability feed

Vulnerability record · CVE-2023-1177 · published 24 March 2023

CVE-2023-1177: MLflow path traversal via backslash filename before 2.2.1

Lfprojects · Mlflow

MLflow versions prior to 2.2.1 are vulnerable to a path traversal flaw (CWE-22/CWE-29) where a crafted '\..\filename' input escapes the intended directory. The issue is remotely reachable with no authentication or user interaction, and a public exploit reference exists, making it a serious risk for exposed MLflow instances.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.7% CWE-29 · CWE-29CWE-22 · Path traversal
9.8CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and a public exploit reference plus very high EPSS make this an urgent patch.

What it is

MLflow versions prior to 2.2.1 are vulnerable to a path traversal flaw (CWE-22/CWE-29) where a crafted '\..\filename' input escapes the intended directory. The issue is remotely reachable with no authentication or user interaction, and a public exploit reference exists, making it a serious risk for exposed MLflow instances.

Impact

An attacker can read and write files outside the intended directory, potentially leading to data exposure or code execution depending on what files are reachable. The CVSS 3.1 score of 9.8 reflects high confidentiality, integrity, and availability impact.

Attack surface

Reached over the network via HTTP with no authentication (PR:N) and no user interaction (UI:N) per the CVSS vector. Any network-exposed MLflow service running a version before 2.2.1 is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is 0.6968 (99.3rd percentile), indicating high predicted exploitation activity. A public exploit reference is tagged in the advisory, so working exploit code is likely available.

What to do

  • Upgrade MLflow to 2.2.1 or later, applying the patch commit referenced in the advisory.
  • Restrict network access to MLflow tracking and model registry endpoints to trusted networks or authenticated proxies.
  • Run MLflow with least-privilege filesystem permissions so traversal cannot reach sensitive files.
  • Monitor for and block path traversal patterns such as '\..\' in request paths at the reverse proxy or WAF.

Detection

  • Inspect MLflow access logs for request paths containing '\..\' or encoded traversal sequences.
  • Alert on file access outside the MLflow artifact or tracking directories by the MLflow process.
  • Use file integrity monitoring on directories reachable by the MLflow service to catch unexpected reads or writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1177 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-64849MLflow unauthenticated webhook test endpoint SSRF via redirectMLflow before 3.15.0 validates the webhook URL only on the original request, while the delivery code follows redirects and re-resolves the hostname w…KEVEPSS 9.8%analysed10.0CVE-2025-15379Lfprojects mlflow command injection vulnerabilityA command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to…EPSS 2.4%10.0CVE-2025-15036Lfprojects mlflow path traversal vulnerabilityA path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf…EPSS 0.58%10.0CVE-2023-3765MLflow absolute path traversal before 2.5.0MLflow versions prior to 2.5.0 contain an absolute path traversal flaw (CWE-36) in the GitHub repository mlflow/mlflow. The vulnerability allows an u…EPSS 68%analysed9.8CVE-2026-0545Lfprojects mlflow missing authentication for critical function vulnerabilityIn mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…EPSS 4.4%9.8CVE-2025-11200Lfprojects mlflow weak password requirements vulnerabilityMLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…EPSS 1.5%9.8CVE-2025-11201Lfprojects mlflow path traversal vulnerabilityMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …EPSS 27%9.8CVE-2023-6974Lfprojects mlflow server-side request forgery (ssrf) vulnerabilityA malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-1177), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.