
A critical path traversal vulnerability (CVE-2025-15036) has been identified in MLflow with a CVSS score of 9.6. The extract_archive_to_dir function within mlflow/pyfunc/dbconnect_artifact_cache.py lacks validation of tar member paths during extraction. An attacker with control over a tar.gz file can exploit this to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory entirely. This is especially dangerous in multi-tenant or shared cluster environments, and affects all versions before v3.7.0. Stay safe by upgrading to MLflow v3.7.0 or later and restricting access to untrusted tar.gz archives until you've patched. Path Traversal in mlflow - CVE-2025-15036 https://devhub.checkmarx.com/cve-details/cve-2025-15036/
Post summary
A critical path traversal vulnerability (CVE‑2025‑15036) in MLflow with a CVSS score of 9.6 is disclosed; users are advised to upgrade to v3.7.0 or later and block untrusted tar.gz files.







