id: PYSEC-2026-1647 published: "2026-07-07T11:45:45.300777Z" modified: "2026-07-07T17:24:42.458910Z" aliases: - CVE-2024-37060 - GHSA-cv6c-7963-wxcg summary: MLFlow unsafe deserialization details: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run. affected: - package: name: mlflow ecosystem: PyPI purl: pkg:pypi/mlflow ranges: - type: ECOSYSTEM events: - introduced: 1.27.0 - last_affected: 2.14.1 versions: - 1.27.0 - 1.28.0 - 1.29.0 - 1.30.0 - 1.30.1 - 2.0.0 - 2.0.0rc0 - 2.0.1 - 2.1.0 - 2.1.1 - 2.10.0 - 2.10.1 - 2.10.2 - 2.11.0 - 2.11.1 - 2.11.2 - 2.11.3 - 2.11.4 - 2.12.0 - 2.12.1 - 2.12.2 - 2.13.0 - 2.13.1 - 2.13.2 - 2.14.0 - 2.14.0rc0 - 2.14.1 - 2.2.0 - 2.2.1 - 2.2.2 - 2.3.0 - 2.3.1 - 2.3.2 - 2.4.0 - 2.4.1 - 2.4.2 - 2.5.0 - 2.6.0 - 2.7.0 - 2.7.1 - 2.8.0 - 2.8.1 - 2.9.0 - 2.9.1 - 2.9.2 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-37060 - type: PACKAGE url: https://github.com/mlflow/mlflow - type: WEB url: https://hiddenlayer.com/sai-security-advisory/mlflow-june2024 - type: PACKAGE url: https://pypi.org/project/mlflow - type: ADVISORY url: https://github.com/advisories/GHSA-cv6c-7963-wxcg severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H