Vulnerability record · CVE-2023-6018 · published 16 November 2023
CVE-2023-6018: MLflow unauthenticated arbitrary file overwrite via command injection
Lfprojects · Mlflow
MLflow, the LF Projects machine learning lifecycle platform, allows an unauthenticated attacker to overwrite any file on the server. The flaw is classified as OS command injection (CWE-78) and carries a CVSS 3.1 base score of 9.8 (critical). Because no authentication or user interaction is required, any network-reachable MLflow instance is at risk.
Description
An attacker can overwrite any file on the server hosting MLflow without any authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and public exploit details plus high EPSS make this an urgent patching priority.
What it is
MLflow, the LF Projects machine learning lifecycle platform, allows an unauthenticated attacker to overwrite any file on the server. The flaw is classified as OS command injection (CWE-78) and carries a CVSS 3.1 base score of 9.8 (critical). Because no authentication or user interaction is required, any network-reachable MLflow instance is at risk.
Impact
An attacker can overwrite arbitrary files on the host, which can lead to code execution, configuration tampering, or full server compromise. The CVSS vector shows high confidentiality, integrity, and availability impact.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N). Any exposed MLflow service is directly attackable without credentials.
Exploitation
Not listed in CISA KEV, but EPSS is 0.47874 (98.8th percentile) and the references include an exploit and technical description, indicating public exploitation detail is available.
What to do
- Patch MLflow to a fixed version as soon as an official release is available.
- Restrict network access to MLflow instances using firewalls, VPNs, or private networking; do not expose them to the internet.
- Run MLflow with least privilege and in a container or sandbox to limit file overwrite impact.
- Monitor for unexpected file changes on MLflow hosts and alert on writes to sensitive paths.
- If patching is not possible, place MLflow behind an authenticating reverse proxy and disable unused endpoints.
Detection
- Monitor MLflow server logs for anomalous requests that may trigger command injection.
- Use file integrity monitoring to detect unexpected modifications to application, configuration, or system files.
- Watch for outbound network connections or process creation from the MLflow service account.
- Audit access logs for unauthenticated requests to MLflow endpoints from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30 | ExploitTechnical DescriptionThird Party Advisory |
| https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2023-6018 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.