← Vulnerability feed

Vulnerability record · CVE-2023-6018 · published 16 November 2023

CVE-2023-6018: MLflow unauthenticated arbitrary file overwrite via command injection

Lfprojects · Mlflow

MLflow, the LF Projects machine learning lifecycle platform, allows an unauthenticated attacker to overwrite any file on the server. The flaw is classified as OS command injection (CWE-78) and carries a CVSS 3.1 base score of 9.8 (critical). Because no authentication or user interaction is required, any network-reachable MLflow instance is at risk.

9.8 CVSS 3.1 Critical EPSS 48% · top 1.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An attacker can overwrite any file on the server hosting MLflow without any authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, and public exploit details plus high EPSS make this an urgent patching priority.

What it is

MLflow, the LF Projects machine learning lifecycle platform, allows an unauthenticated attacker to overwrite any file on the server. The flaw is classified as OS command injection (CWE-78) and carries a CVSS 3.1 base score of 9.8 (critical). Because no authentication or user interaction is required, any network-reachable MLflow instance is at risk.

Impact

An attacker can overwrite arbitrary files on the host, which can lead to code execution, configuration tampering, or full server compromise. The CVSS vector shows high confidentiality, integrity, and availability impact.

Attack surface

Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N). Any exposed MLflow service is directly attackable without credentials.

Exploitation

Not listed in CISA KEV, but EPSS is 0.47874 (98.8th percentile) and the references include an exploit and technical description, indicating public exploitation detail is available.

What to do

  • Patch MLflow to a fixed version as soon as an official release is available.
  • Restrict network access to MLflow instances using firewalls, VPNs, or private networking; do not expose them to the internet.
  • Run MLflow with least privilege and in a container or sandbox to limit file overwrite impact.
  • Monitor for unexpected file changes on MLflow hosts and alert on writes to sensitive paths.
  • If patching is not possible, place MLflow behind an authenticating reverse proxy and disable unused endpoints.

Detection

  • Monitor MLflow server logs for anomalous requests that may trigger command injection.
  • Use file integrity monitoring to detect unexpected modifications to application, configuration, or system files.
  • Watch for outbound network connections or process creation from the MLflow service account.
  • Audit access logs for unauthenticated requests to MLflow endpoints from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30 ExploitTechnical DescriptionThird Party Advisory
https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2023-6018 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-64849MLflow unauthenticated webhook test endpoint SSRF via redirectMLflow before 3.15.0 validates the webhook URL only on the original request, while the delivery code follows redirects and re-resolves the hostname w…KEVEPSS 9.8%analysed10.0CVE-2025-15379Lfprojects mlflow command injection vulnerabilityA command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to…EPSS 2.4%10.0CVE-2025-15036Lfprojects mlflow path traversal vulnerabilityA path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf…EPSS 0.58%10.0CVE-2023-3765MLflow absolute path traversal before 2.5.0MLflow versions prior to 2.5.0 contain an absolute path traversal flaw (CWE-36) in the GitHub repository mlflow/mlflow. The vulnerability allows an u…EPSS 68%analysed9.8CVE-2026-0545Lfprojects mlflow missing authentication for critical function vulnerabilityIn mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…EPSS 4.4%9.8CVE-2025-11200Lfprojects mlflow weak password requirements vulnerabilityMLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…EPSS 1.5%9.8CVE-2025-11201Lfprojects mlflow path traversal vulnerabilityMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …EPSS 27%9.8CVE-2023-6974Lfprojects mlflow server-side request forgery (ssrf) vulnerabilityA malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-6018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.