
🚨*CVE* CVE-2026-4137 In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable … https://www.cve.org/CVERecord?id=CVE-2026-4137 ----- Traducción: CVE-2026-4137 En … http://infoflow.cloud`
Post summary
The post announces CVE-2026-4137, a vulnerability in mlflow before version 3.11.0 where the get_or_create_nfs_tmp_dir() function creates world‑writable temp directories, potentially exposing the system to privilege escalation or information disclosure.

