GPU VulnDB

Database/AI/ML frameworks & serving

MLflow (recipes / pyfunc): RCE via a maliciously crafted MLproject

CVE-2024-37061AI/ML frameworks & servingcurated

Impact

RCE via a maliciously crafted MLproject

Who can reach it

Customer-supplied MLproject/recipe run by the platform

What to do

Upgrade. If the provider runs a managed MLflow, tenant projects execute in the provider plane

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.