CVE-2024-37054
HIGH 8.8EPSS 0.7%
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS
- 0.70% chance of exploitation in the next 30 days, 51th percentile
- Published
- 2024-06-04
- Updated
- 2024-08-02
Proof-of-concept exploits (4)
- NiteeshPujari/CVE-2024-37054-MLflow-RCE3★ · 2025-08-22
- ben-slates/CVE-2024-37054
- jimmexploit/CVE-2024-37054-PoC
- tristanqtn/CVE-2024-37054