GPU VulnDB

Database/AI/ML frameworks & serving

MLflow (serving container init): Command injection in `_install_model_dependencies`

CVE-2025-15379AI/ML frameworks & servingcurated

Impact

Command injection in _install_model_dependencies

Who can reach it

Customer-supplied model requirements consumed when the provider builds a serving container

What to do

Provider-owned in managed serving: the tenant's requirements file executes shell in the build

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.