CVE-2023-1177Active Exploitation(lfprojects / mlflow)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for lfprojects mlflow systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-29CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Active exploitation appears in 2 classified signals
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-08); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-08: 1Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-05: 1Technical Details · 2026-05-04: 103-0805-0405-05
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Classification over time
DateTotalLabels
2026-03-081
General1
2026-05-041
Active Exploitation1
2026-05-051
Active Exploitation1
Full discourse3 posts
  • NoHeartz@Noheartz1337
    General

    If this doesn't work, I'll be really pissed off 🗿... CVE-2021-46381 CVE-2022-0679 CVE-2023-1177 CVE-2024-12987 CVE-2025-47813 #NoHeartz #CVE #CommonVulnerabilitiesExposures #CyberNews #CyberAttack https://t.co/hrDFVeNHj0

    Post summary

    The tweet merely lists several CVE identifiers without providing any additional context or details about exploits, patches, or vulnerability specifics.

    00010200
    4 followersView on X
  • NuClide@n15647931
    Active Exploitation

    MLOps (MLflow Tracking) — 11 instances, 100% unauthenticated — and 18% actively being exploited via CVE-2023-1177, with attacker-injected experiments doubling overnight between probes

    Post summary

    The passage reports that 18% of the identified MLflow Tracking instances are being actively exploited through CVE‑2023‑1177, with attacker‑injected experiments doubling overnight.

    0000059
    48 followersView on X
  • NuClide@n15647931
    Active Exploitation

    visible attacker activity. dozens of attacker-injected experiments. Same actor (matching 3BT8ncOzBWAH4GyIGz0EXsSwj7f ID) is spraying CVE-2023-1177 path-traversal payloads across vulnerable MLflow servers in the wild, harvesting SSH keys. https://t.co/tsj8jap8cg

    Post summary

    Attackers are actively exploiting CVE‑2023‑1177 on MLflow servers, using path‑traversal payloads to harvest SSH keys.

    0000068
    48 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more