Vulnerability record · CVE-2023-6909 · published 18 December 2023
CVE-2023-6909: MLflow path traversal via backslash filename reads arbitrary files
Lfprojects · Mlflow
MLflow versions prior to 2.9.2 are vulnerable to a path traversal flaw using a '\..\filename' sequence (CWE-29). An unauthenticated remote attacker can craft a request that escapes the intended directory and reads files outside it. The issue is fixed in 2.9.2 by commit 1da75dfc.
Description
Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 and a very high EPSS with public exploit detail make this a high-priority unauthenticated file-read flaw, though it is not in KEV and has no confirmed in-the-wild exploitation.
What it is
MLflow versions prior to 2.9.2 are vulnerable to a path traversal flaw using a '\..\filename' sequence (CWE-29). An unauthenticated remote attacker can craft a request that escapes the intended directory and reads files outside it. The issue is fixed in 2.9.2 by commit 1da75dfc.
Impact
An attacker gains read access to files on the MLflow server that are otherwise outside the intended directory, potentially exposing configuration, credentials or model artifacts. There is no integrity or availability impact per the CVSS vector.
Attack surface
The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the MLflow service can attempt it. The description does not name the specific endpoint, so the exact request path is not confirmed in this record.
Exploitation
CVE-2023-6909 is not listed in CISA KEV, but EPSS is very high at 0.897 (99.8th percentile), and the Huntr reference is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.
What to do
- Upgrade MLflow to 2.9.2 or later, which contains the fix in commit 1da75dfc.
- If immediate upgrade is not possible, restrict network access to the MLflow service to trusted hosts only.
- Run MLflow with least privilege so a traversal read cannot reach sensitive files.
- Review the Huntr advisory and patch commit to confirm which endpoint is affected and add a targeted filter if needed.
Detection
- Monitor MLflow request logs for filenames containing '..' or backslash traversal sequences.
- Alert on file-read activity by the MLflow process outside its expected data and artifact directories.
- Check for access to sensitive paths such as configuration or credential files from the MLflow service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mlflow/mlflow/commit/1da75dfcecd4d169e34809ade55748384e8af6c1 | Patch |
| https://huntr.com/bounties/11209efb-0f84-482f-add0-587ea6b7e850 | ExploitPatchThird Party Advisory |
| https://github.com/mlflow/mlflow/commit/1da75dfcecd4d169e34809ade55748384e8af6c1 | Patch |
| https://huntr.com/bounties/11209efb-0f84-482f-add0-587ea6b7e850 | ExploitPatchThird Party Advisory |
Track CVE-2023-6909 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6909), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.