Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14287

Опубликовано: 15 мар. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the mlflow/sagemaker/__init__.py file at lines 161-167. The vulnerability arises from the direct interpolation of user-supplied container image names into shell commands without proper sanitization, which are then executed using os.system(). This allows attackers to execute arbitrary commands by supplying malicious input through the --container parameter of the CLI. The issue affects environments where MLflow is used, including development setups, CI/CD pipelines, and cloud deployments.

A flaw was found in MLflow, a platform for managing the machine learning lifecycle. This vulnerability, known as command injection, allows an attacker to execute unauthorized commands on the system. By providing specially crafted input through the --container parameter, an attacker can bypass security checks and inject malicious code. This can lead to arbitrary command execution, potentially compromising the integrity and confidentiality of the affected system.

Отчет

Important: A command injection flaw in MLflow allows arbitrary command execution by supplying malicious input to the --container parameter. This vulnerability impacts Red Hat OpenShift AI deployments where MLflow is utilized, potentially compromising system integrity and confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-training-cuda128-torch29-py312-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2447690mlflow: MLflow: Arbitrary command execution via unsanitized container image names

EPSS

Процентиль: 71%
0.01456
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct interpolation of user-supplied container image names into shell commands without proper sanitization, which are then executed using `os.system()`. This allows attackers to execute arbitrary commands by supplying malicious input through the `--container` parameter of the CLI. The issue affects environments where MLflow is used, including development setups, CI/CD pipelines, and cloud deployments.

CVSS3: 7.5
github
5 месяцев назад

MLflow has a command injection in mlflow/sagemaker/__init__.py

CVSS3: 7.5
fstec
8 месяцев назад

Уязвимость функции os.system() платформы управления жизненным циклом моделей машинного обучения MLflow, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 71%
0.01456
Низкий

7.8 High

CVSS3