CVE-2025-15379Disclosure(lfprojects / mlflow)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch lfprojects mlflow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` file and directly interpolates them into a shell command without sanitization. This allows an attacker to supply a malicious model artifact and achieve arbitrary command execution on systems that deploy the model. The vulnerability affects versions 3.8.0 and is fixed in version 3.8.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-30); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-30: 4Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-03-30: 4Technical Details · 2026-04-01: 103-3003-3104-01
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-304
Disclosure3Patch1
2026-03-312
General2
2026-04-011
Disclosure1
Full discourse7 posts
  • cole murray@_colemurray
    General

    everyone is now panicking about AI hacking we've been AI hacking 10.0 critical in MLFlow by AI security agent waclaude (button pushed by me lol) CVE-2025-15379 https://t.co/P8zC6x5KlE

    Post summary

    The tweet references CVE-2025-15379 but offers no concrete details, exploitation evidence, or remediation information.

    1011362.3K
    4.1K followersView on X
  • cole murray@_colemurray
    General

    you can read the NVD report here: https://nvd.nist.gov/vuln/detail/CVE-2025-15379

    Post summary

    The post merely provides a link to the NVD report for CVE‑2025‑15379 with no additional context or details.

    00041412
    3.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-15379: CRITICAL] Critical command injection vulnerability in MLflow version 3.8.0 enables arbitrary command execution. Upgrade to version 3.8.2 to fix the security flaw. #CyberSecurity#cve,CVE-2025-15379,#cybersecurity https://cvefind.com/CVE-2025-15379

    Post summary

    A critical command injection vulnerability in MLflow 3.8.0 is disclosed, and users are advised to upgrade to version 3.8.2 to mitigate the issue.

    0000184
    617 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `MLflow` is vulnerable to command injection (CVE-2025-15379), potentially allowing arbitrary code execution. Assess impact in your `MLflow` deployments. #MLflow #CommandInjection #InfoSec https://www.pulsepatch.io/posts/cve-2025-15379-mlflow-command-injection

    Post summary

    The post alerts that MLflow is vulnerable to command injection (CVE‑2025‑15379), allowing arbitrary code execution, and urges users to assess the impact of the flaw.

    00000192
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15379 A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function.… https://www.cve.org/CVERecord?id=CVE-2025-15379

    Post summary

    The CVE‑2025‑15379 reveals a command injection flaw in MLflow’s model serving initialization code, but no proof of concept, exploit, or patch information is provided.

    00000119
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-15379 - Critical A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a mod... https://www.thehackerwire.com/vulnerability/CVE-2025-15379/ https://t.co/FuHN61P2CN

    Post summary

    The tweet announces a critical command injection vulnerability in MLflow’s model serving container initialization, highlighting the affected function but lacking exploit, patch, or active exploitation details.

    00000199
    163 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-15379: Command Injection in mlflow/mlfl... MLflow's `python_env.yaml` parsing becomes a shell injection goldmine - malicious model artifacts = instant RCE on depl... https://zerodaysignal.com/vulnerability/CVE-2025-15379 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a command‑injection flaw in MLflow’s python_env.yaml parsing that allows RCE, but provides no PoC, exploit, or patch information.

    00000236
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more