
CVE-2025-15381 In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows… https://www.cve.org/CVERecord?id=CVE-2025-15381
Post summary
The text announces CVE-2025-15381, highlighting that in mlflow’s latest release, enabling basic‑auth leaves certain endpoints unprotected, exposing them to unauthorized access.

