
🚨 Critical - MLflow Assistant Origin Validation Bypass Leads to RCE (CVE-2026-2611) MLflow Assistant contains an improper origin validation vulnerability in /ajax-api endpoints that allows malicious websites to interact with a locally running MLflow instance. Successful exploitation may let attackers modify Assistant settings and execute arbitrary commands through the Claude Code sub-agent. 👉 Affected: MLflow 3.9.0 | Fix: Upgrade to MLflow 3.10.0 immediately
Post summary
The post announces CVE-2026-2611, a RCE vulnerability caused by improper origin validation in MLflow Assistant, and urges an immediate upgrade to version 3.10.0.

