Cross-site Scripting in MLFlow
Critical severity
GitHub Reviewed
Published
Feb 24, 2024
to the GitHub Advisory Database
•
Updated Jan 22, 2025
Description
Published by the National Vulnerability Database
Feb 23, 2024
Published to the GitHub Advisory Database
Feb 24, 2024
Reviewed
Feb 26, 2024
Last updated
Jan 22, 2025
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.
The vulnerability stems from lack of sanitization over template variables.
References