CVE-2025-15036Disclosure(lfprojects / mlflow)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects mlflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extraction. An attacker with control over the tar.gz file can exploit this issue to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory in multi-tenant or shared cluster environments.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-29CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 6 mentions (2026-03-30); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-03-30: 6Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-30: 5Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 103-3004-0104-02
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-306
Disclosure6
2026-04-011
Patch1
2026-04-021
Patch1
Full discourse8 posts
  • Checkmarx Zero@CheckmarxZero
    Patch

    A critical path traversal vulnerability (CVE-2025-15036) has been identified in MLflow with a CVSS score of 9.6. The extract_archive_to_dir function within mlflow/pyfunc/dbconnect_artifact_cache.py lacks validation of tar member paths during extraction. An attacker with control over a tar.gz file can exploit this to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory entirely. This is especially dangerous in multi-tenant or shared cluster environments, and affects all versions before v3.7.0. Stay safe by upgrading to MLflow v3.7.0 or later and restricting access to untrusted tar.gz archives until you've patched. Path Traversal in mlflow - CVE-2025-15036 https://devhub.checkmarx.com/cve-details/cve-2025-15036/

    Post summary

    A critical path traversal vulnerability (CVE‑2025‑15036) in MLflow with a CVSS score of 9.6 is disclosed; users are advised to upgrade to v3.7.0 or later and block untrusted tar.gz files.

    00010153
    228 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical path traversal vulnerability (CVE-2025-15036) has been identified in `MLFlow`. This flaw could allow unauthorized access to sensitive files. Assess your #MLFlow deployments and prepare for #patching. More details: https://www.pulsepatch.io/posts/cve-2025-15036-mlflow-path-traversal

    Post summary

    The advisory announces a critical path‑traversal flaw in MLFlow that could expose sensitive files and urges users to evaluate deployments and prepare for patching.

    00000194
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-15036 📊 Severity: 9.6 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-15036 #CVE-2025-15036 #CVE #Critical #CyberSecurity #InfoSec https://t.co/i7olyMNzuP

    Post summary

    The tweet announces the existence of a new high‑severity CVE (CVE‑2025‑15036) but provides no technical, PoC, or exploitation details.

    00000229
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15036 A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow reposi… https://www.cve.org/CVERecord?id=CVE-2025-15036

    Post summary

    The snippet announces a path traversal flaw in the mlflow 'extract_archive_to_dir' function, but provides no PoC, exploit, or patch details.

    00000101
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15036 - Path Traversal Vulnerability in mlflow/mlflow Intel Report: https://ift.tt/RByO3xT

    Post summary

    The alert announces a newly identified Path Traversal vulnerability in mlflow/mlflow (CVE-2025-15036) and links to an Intel Report, without indicating any PoC, exploit, or patch information.

    00000190
    281 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-15036: CRITICAL] Critical path traversal vulnerability identified in mlflow repository's `extract_archive_to_dir` function allowing attackers to overwrite files or attain higher privileges pre v3.7.0.#cve,CVE-2025-15036,#cybersecurity https://cvefind.com/CVE-2025-15036

    Post summary

    A newly disclosed critical path traversal vulnerability in mlflow's extract_archive_to_dir function that can lead to file overwrite or privilege escalation.

    00000100
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-15036 - Critical A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerabil... https://www.thehackerwire.com/vulnerability/CVE-2025-15036/ https://t.co/0ZsC4YNqu0

    Post summary

    A critical path‑traversal vulnerability (CVE‑2025‑15036) has been disclosed in the mlflow/mlflow repository's artifact cache extract function.

    00000196
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-15036: Path Traversal Vulnerability in ... MLFlow's tar extraction bypasses path validation—classic zip slip in ML pipelines means one malicious model archive own... https://zerodaysignal.com/vulnerability/CVE-2025-15036 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces that CVE-2025-15036 is a path traversal flaw in MLFlow’s tar extraction, highlighting classic zip slip, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000251
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more