CVE-2025-15381

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.
References
Link Resource
https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c Third Party Advisory Exploit
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:*

History

28 Apr 2026, 14:32

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 7.1
References () https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c - () https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c - Third Party Advisory, Exploit
CPE cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:*
First Time Lfprojects mlflow
Lfprojects
CWE NVD-CWE-noinfo

27 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 17:16

Updated : 2026-04-28 14:32


NVD link : CVE-2025-15381

Mitre link : CVE-2025-15381

CVE.ORG link : CVE-2025-15381


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo