id: PYSEC-2026-2656 published: "2026-07-13T14:36:43.722768Z" modified: "2026-07-13T16:04:53.818081Z" aliases: - CVE-2025-15031 - GHSA-fhff-qmm8-h2fp summary: Arbitrary file write via tar traversal in mlflow details: A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables crafted tar.gz files containing `..` or absolute paths to escape the intended extraction directory. This issue affects the latest version of MLflow and poses a high/critical risk in scenarios involving multi-tenant environments or ingestion of untrusted artifacts, as it can lead to arbitrary file overwrites and potential remote code execution. affected: - package: name: mlflow ecosystem: PyPI purl: pkg:pypi/mlflow ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 3.9.0rc0 versions: - 0.0.1 - 0.1.0 - 0.2.0 - 0.2.1 - 0.3.0 - 0.4.0 - 0.4.1 - 0.4.2 - 0.5.0 - 0.5.1 - 0.5.2 - 0.6.0 - 0.7.0 - 0.8.0 - 0.8.1 - 0.8.2 - 0.9.0 - 0.9.0.1 - 0.9.1 - 1.0.0 - 1.1.0 - 1.1.1.dev0 - 1.10.0 - 1.11.0 - 1.12.0 - 1.12.1 - "1.13" - 1.13.1 - 1.14.0 - 1.14.1 - 1.15.0 - 1.16.0 - 1.17.0 - 1.18.0 - 1.19.0 - 1.2.0 - 1.20.0 - 1.20.1 - 1.20.2 - 1.21.0 - 1.22.0 - 1.23.0 - 1.23.1 - 1.24.0 - 1.25.0 - 1.25.1 - 1.26.0 - 1.26.1 - 1.27.0 - 1.28.0 - 1.29.0 - 1.3.0 - 1.30.0 - 1.30.1 - 1.4.0 - 1.5.0 - 1.6.0 - 1.7.0 - 1.7.1 - 1.7.2 - 1.8.0 - 1.9.0 - 1.9.1 - 2.0.0 - 2.0.0rc0 - 2.0.1 - 2.1.0 - 2.1.1 - 2.10.0 - 2.10.1 - 2.10.2 - 2.11.0 - 2.11.1 - 2.11.2 - 2.11.3 - 2.11.4 - 2.12.0 - 2.12.1 - 2.12.2 - 2.13.0 - 2.13.1 - 2.13.2 - 2.14.0 - 2.14.0rc0 - 2.14.1 - 2.14.2 - 2.14.2.dev0 - 2.14.3 - 2.15.0 - 2.15.0rc0 - 2.15.1 - 2.16.0 - 2.16.1 - 2.16.2 - 2.17.0 - 2.17.0rc0 - 2.17.1 - 2.17.2 - 2.18.0 - 2.18.0rc0 - 2.19.0 - 2.19.0rc0 - 2.2.0 - 2.2.1 - 2.2.2 - 2.20.0 - 2.20.0rc0 - 2.20.1 - 2.20.2 - 2.20.3 - 2.20.4 - 2.21.0 - 2.21.0rc0 - 2.21.1 - 2.21.2 - 2.21.3 - 2.22.0 - 2.22.0rc0 - 2.22.1 - 2.22.2 - 2.22.3 - 2.22.4 - 2.22.5 - 2.3.0 - 2.3.1 - 2.3.2 - 2.4.0 - 2.4.1 - 2.4.2 - 2.5.0 - 2.6.0 - 2.7.0 - 2.7.1 - 2.8.0 - 2.8.1 - 2.9.0 - 2.9.1 - 2.9.2 - 3.0.0 - 3.0.0rc0 - 3.0.0rc1 - 3.0.0rc2 - 3.0.0rc3 - 3.0.1 - 3.1.0 - 3.1.0rc0 - 3.1.1 - 3.1.2 - 3.1.3 - 3.1.4 - 3.2.0 - 3.2.0rc0 - 3.3.0 - 3.3.0rc0 - 3.3.1 - 3.3.2 - 3.4.0 - 3.4.0rc0 - 3.5.0 - 3.5.0rc0 - 3.5.1 - 3.6.0 - 3.6.0rc0 - 3.7.0 - 3.7.0rc0 - 3.8.0 - 3.8.0rc0 - 3.8.1 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-15031 - type: WEB url: https://github.com/mlflow/mlflow/commit/3bf6d81ac4d38654c8ff012dbd0c3e9f17e7e346 - type: PACKAGE url: https://github.com/mlflow/mlflow - type: WEB url: "https://github.com/mlflow/mlflow/blob/fe4d9be330426904283401f1d2ed914238b6fc37/mlflow/pyfunc/dbconnect_artifact_cache.py#L140" - type: WEB url: https://huntr.com/bounties/09856f77-f968-446f-a930-657d126efe4e - type: PACKAGE url: https://pypi.org/project/mlflow - type: ADVISORY url: https://github.com/advisories/GHSA-fhff-qmm8-h2fp severity: - type: CVSS_V3 score: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N