CVE-2025-15381

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:*

History

30 Jun 2026, 03:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2025-15381 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2452341 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15381.json -
CWE CWE-425

17 Jun 2026, 08:37

Type Values Removed Values Added
References () https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c - Third Party Advisory, Exploit () https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c - Exploit, Third Party Advisory

28 Apr 2026, 14:32

Type Values Removed Values Added
References () https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c - () https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c - Third Party Advisory, Exploit
CPE cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Lfprojects mlflow
Lfprojects
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 7.1

27 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 17:16

Updated : 2026-07-15 02:17


NVD link : CVE-2025-15381

Mitre link : CVE-2025-15381

CVE.ORG link : CVE-2025-15381


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo CWE-425

Direct Request ('Forced Browsing')