
CVE-2026-33865 MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can… https://www.cve.org/CVERecord?id=CVE-2026-33865
Post summary
The post announces a stored XSS flaw in MLflow’s web UI due to YAML parsing, but provides no PoC, exploit, patch, or evidence of active exploitation.


