Threat intelligence, Threat Research

Attackers Target MLflow AI Model Registry to Exfiltrate Server Files via Path Traversal

by Ashwini Bhagwat

Attackers Target MLflow AI Model Registry to Exfiltrate Server Files via Path Traversal

Overview

MLflow is one of the most widely deployed open-source platforms for managing the machine learning lifecycle, from experiment tracking and model versioning to deployment and registry management. Originally developed at Databricks and now hosted under the Linux Foundation, MLflow is a standard fixture in enterprise AI/ML pipelines at thousands of organizations worldwide.

Through its honeypot network, the SonicWall Capture Labs threat research team has observed active in-the-wild exploitation attempts targeting MLflow deployments. The attack campaign exploits CVE-2023-6977, a path traversal vulnerability in the MLflow model registry API that allows unauthenticated attackers to read arbitrary files from the server filesystem, including sensitive credentials, private keys, and environment variable files. A second vulnerability, CVE-2024-27132, is exploited in tandem via the model name field to inject content into MLflow's web interface.

CVE-2023-6977 Vulnerability Summary

CVSS Score

7.5 HIGH

Type

Path Traversal / Arbitrary File Read

CWE

CWE-29 Path Traversal

Attack Vector

Network / No Auth / No User Interaction

Affected Product

MLflow (LF Projects)

Affected Version

1.0.0 – 2.9.1 (fixed in 2.9.2)

NVD Reference

nvd.nist.gov/vuln/detail/CVE-2023-6977 ↗

CVE-2024-27132 Vulnerability Summary

CVSS Score

9.6 CRITICAL

Type

XSS / Client-Side RCE

CWE

CWE-79 Improper Input Neutralization

Attack Vector

Network / No Auth / User Interaction Required

Affected Product

MLflow (LF Projects)

Affected Version

0 – 2.9.2 (fixed in 2.9.2)

NVD Reference

nvd.nist.gov/vuln/detail/CVE-2024-27132 ↗

Notably, this campaign targets the model version source and experiment artifact_location parameters, which MLflow uses to resolve file paths for loading model artifacts. Attackers supply file:// URIs and Linux /proc filesystem references instead of legitimate model paths, causing the server to expose its own files. A proof-of-concept exploit is publicly available, and public-facing MLflow instances without authentication are actively being scanned and exploited.

Technical Overview

MLflow's model registry exposes three REST API endpoints that are central to this attack:

  • POST /api/2.0/mlflow/registered-models/create: creates a named model entry in the registry
  • POST /api/2.0/mlflow/model-versions/create: creates a versioned artifact under a model, specifying a source path
  • POST /api/2.0/mlflow/experiments/create: creates an experiment with an artifact_location URI

In vulnerable versions, MLflow fails to sanitize or restrict the source parameter in model-versions/create and the artifact_location parameter in experiments/create. Both parameters accept file:// URIs and path traversal sequences. When the server subsequently attempts to access the artifact at the supplied path, it reads and exposes the contents of files outside the intended model artifact directory, including anything the MLflow server process has read access to.

Additionally, CVE-2024-27132 allows arbitrary content injection via the model name field, which in vulnerable versions is rendered without sanitization in the MLflow experiment UI. In Jupyter Notebook environments, a common deployment pattern for data science teams, this can escalate to client-side code execution.

MLflow is routinely deployed without authentication on internal networks or exposed directly to the internet by data science teams who prioritize accessibility over security hardening. A single unauthenticated HTTP request is sufficient to trigger CVE-2023-6977: there is no credential requirement, no session token, and no rate limiting in default deployments.

Attack Chain

The honeypot capture reveals a structured three-stage exploit sequence. All requests originate from a single source IP (45[.]138[.]12[.]49) and use a consistent model name token, indicating an automated exploit toolkit:

MLFlow_0.png

Triggering the Vulnerabilities

The following HTTP requests were captured by the SonicWall honeypot. User-Agent strings are rotated across Linux, Windows, and macOS variants to evade detection, a clear indicator of an automated exploit toolkit.

Stage 1: Register Model Name (CVE-2024-27132 Injection Point)

MLFlow_1.png

The name field is the injection vector for CVE-2024-27132. The token 3JPHcs… appears across all requests in this campaign, functioning as a session identifier generated by the exploit toolkit. When this name is rendered unsanitized in the MLflow UI, it can carry XSS payloads.

Stage 2: Path Traversal via Model Version source (CVE-2023-6977)

The attacker creates model versions with the source parameter set to various path traversal and file URI payloads:

MLFlow_2.pngMLFlow_3.pngMLFlow_4.png

Stage 3: Path Traversal via Experiment artifact_location

MLFlow_5.png
Payload Analysis
PayloadTarget
//proc/self/rootExposes the entire root filesystem via the process's own /proc/self/root symlink, bypassing path restrictions that block / directly
file:///etc/Reads the /etc/ directory and targets /etc/passwd, /etc/shadow, /etc/environment, SSH keys, and service configuration files
file://./etcAlternative evasion form of the /etc traversal; bypasses filters that block absolute file:///etc but allow relative URIs
file://<IP>:443/../../../../../../../Uses the honeypot's own IP as the authority to construct a file URI that traverses back to the server root; also probes for SSRF pivoting to internal services on port 443
http://?/../../../../../../etc/Leverages the artifact_location parameter in experiment creation; the ? null authority bypasses URI validation while the traversal sequences resolve to /etc/ on the server

 

Campaign Fingerprint: The model name token 3JPHcs… appears consistently across the captured requests, suggesting a single automated exploit framework rather than manual exploitation. User-Agent strings (Linux, Windows, macOS, legacy Firefox, modern Chrome/Safari) are rotated per request, a deliberate anti-fingerprinting technique. All requests originate from 45[.]138[.]12[.]49.

SonicWall Protections

To ensure SonicWall customers are prepared for any exploitation that may occur due to this vulnerability, the following signature has been released:

Signature IDSignature Name
IPS 21270MLflow Path Traversal 4
IPS 21374MLflow Artifacts Information Disclosure
IPS 21075MLflow Arbitrary File Download

Indicators of Compromise

  • 45[.]138[.]12[.]49
  • 3JPHcs*

Remediation Recommendations

  • Upgrade MLflow immediately.
  • Never expose MLflow directly to the internet. It has no authentication by default. Place it behind a VPN, a reverse proxy with authentication (e.g., nginx with OAuth2 Proxy), or network ACLs that restrict access to internal IP ranges only.
  • Enable MLflow authentication. Versions 2.5.0 and later include built-in basic authentication (mlflow server --app-name basic-auth). Enable it and enforce strong credentials for all users.
  • Restrict the MLflow server's filesystem permissions. Run the process under a dedicated low-privilege service account with read access limited to the model artifact directory. The process should have no access to /etc/, /proc/, home directories, or credential stores.
  • Audit exposed MLflow instances. Search your infrastructure for deployments listening on default ports (5000, 5001). Use Shodan, Censys, or internal network scans. Any instance accessible without authentication should be treated as compromised and audited for unauthorized model registrations and experiment creation.

Relevant Links

 

Share This Article

An Article By

Ashwini Bhagwat

Senior Threat Researcher
Ashwini Bhagwat is a seasoned cybersecurity professional with a passion for threat hunting and vulnerability analysis. She is a Senior Threat Researcher at SonicWall, where she leads the Microsoft Active Protections Program (MAPP). Ashwini's expertise lies in performing in-depth analysis of vulnerabilities and developing robust protections for IPS (Intrusion Prevention System).

Related Articles

  • H2O-3 Unauthenticated RCE via PostgreSQL JDBC socketFactory
    Read More
  • Mesop AI Sandbox Unauthenticated Remote Code Execution
    Read More