CVE-2026-2611

NONE EPSS 28.9%
Published May 19, 20261mo ago · Modified Jun 17, 20261w ago
Find Similar
Published May 19, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via the Claude Code sub-agent. This issue is resolved in version 3.10.0.

Threat Intelligence

EPSS Exploit Probability
28.9% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-346

Affected Products 1

VendorProductVersionRange
lfprojectsmlflow*≥3.9.0  –  <3.10.0

References 2

  • github.com https://github.com/mlflow/mlflow/commit/8f9c8a53af90842944101eb8b7d60706822c81bc
    Patch
  • huntr.com https://huntr.com/bounties/8462addd-b464-4a84-b6a2-5529604e6e5a
    ExploitThird Party Advisory

Remediation

  • github.com https://github.com/mlflow/mlflow/commit/8f9c8a53af90842944101eb8b7d60706822c81bc
    Patch