Database/AI/ML frameworks & serving
MLflow (serving container init): Command injection in `_install_model_dependencies`
CVE-2025-15379AI/ML frameworks & servingcurated
Impact
Command injection in _install_model_dependencies
Who can reach it
Customer-supplied model requirements consumed when the provider builds a serving container
What to do
Provider-owned in managed serving: the tenant's requirements file executes shell in the build
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.