
MLflow is one of the most widely deployed open-source platforms for managing the machine learning lifecycle, from experiment tracking and model versioning to deployment and registry management. Originally developed at Databricks and now hosted under the Linux Foundation, MLflow is a standard fixture in enterprise AI/ML pipelines at thousands of organizations worldwide.
Through its honeypot network, the SonicWall Capture Labs threat research team has observed active in-the-wild exploitation attempts targeting MLflow deployments. The attack campaign exploits CVE-2023-6977, a path traversal vulnerability in the MLflow model registry API that allows unauthenticated attackers to read arbitrary files from the server filesystem, including sensitive credentials, private keys, and environment variable files. A second vulnerability, CVE-2024-27132, is exploited in tandem via the model name field to inject content into MLflow's web interface.
CVSS Score | 7.5 HIGH |
Type | Path Traversal / Arbitrary File Read |
CWE | CWE-29 Path Traversal |
Attack Vector | Network / No Auth / No User Interaction |
Affected Product | MLflow (LF Projects) |
Affected Version | 1.0.0 – 2.9.1 (fixed in 2.9.2) |
NVD Reference |
CVSS Score | 9.6 CRITICAL |
Type | XSS / Client-Side RCE |
CWE | CWE-79 Improper Input Neutralization |
Attack Vector | Network / No Auth / User Interaction Required |
Affected Product | MLflow (LF Projects) |
Affected Version | 0 – 2.9.2 (fixed in 2.9.2) |
NVD Reference |
Notably, this campaign targets the model version source and experiment artifact_location parameters, which MLflow uses to resolve file paths for loading model artifacts. Attackers supply file:// URIs and Linux /proc filesystem references instead of legitimate model paths, causing the server to expose its own files. A proof-of-concept exploit is publicly available, and public-facing MLflow instances without authentication are actively being scanned and exploited.
MLflow's model registry exposes three REST API endpoints that are central to this attack:
In vulnerable versions, MLflow fails to sanitize or restrict the source parameter in model-versions/create and the artifact_location parameter in experiments/create. Both parameters accept file:// URIs and path traversal sequences. When the server subsequently attempts to access the artifact at the supplied path, it reads and exposes the contents of files outside the intended model artifact directory, including anything the MLflow server process has read access to.
Additionally, CVE-2024-27132 allows arbitrary content injection via the model name field, which in vulnerable versions is rendered without sanitization in the MLflow experiment UI. In Jupyter Notebook environments, a common deployment pattern for data science teams, this can escalate to client-side code execution.
MLflow is routinely deployed without authentication on internal networks or exposed directly to the internet by data science teams who prioritize accessibility over security hardening. A single unauthenticated HTTP request is sufficient to trigger CVE-2023-6977: there is no credential requirement, no session token, and no rate limiting in default deployments.
The honeypot capture reveals a structured three-stage exploit sequence. All requests originate from a single source IP (45[.]138[.]12[.]49) and use a consistent model name token, indicating an automated exploit toolkit:

The following HTTP requests were captured by the SonicWall honeypot. User-Agent strings are rotated across Linux, Windows, and macOS variants to evade detection, a clear indicator of an automated exploit toolkit.

The name field is the injection vector for CVE-2024-27132. The token 3JPHcs… appears across all requests in this campaign, functioning as a session identifier generated by the exploit toolkit. When this name is rendered unsanitized in the MLflow UI, it can carry XSS payloads.
The attacker creates model versions with the source parameter set to various path traversal and file URI payloads:




| Payload | Target |
| //proc/self/root | Exposes the entire root filesystem via the process's own /proc/self/root symlink, bypassing path restrictions that block / directly |
| file:///etc/ | Reads the /etc/ directory and targets /etc/passwd, /etc/shadow, /etc/environment, SSH keys, and service configuration files |
| file://./etc | Alternative evasion form of the /etc traversal; bypasses filters that block absolute file:///etc but allow relative URIs |
| file://<IP>:443/../../../../../../../ | Uses the honeypot's own IP as the authority to construct a file URI that traverses back to the server root; also probes for SSRF pivoting to internal services on port 443 |
| http://?/../../../../../../etc/ | Leverages the artifact_location parameter in experiment creation; the ? null authority bypasses URI validation while the traversal sequences resolve to /etc/ on the server |
Campaign Fingerprint: The model name token 3JPHcs… appears consistently across the captured requests, suggesting a single automated exploit framework rather than manual exploitation. User-Agent strings (Linux, Windows, macOS, legacy Firefox, modern Chrome/Safari) are rotated per request, a deliberate anti-fingerprinting technique. All requests originate from 45[.]138[.]12[.]49.
To ensure SonicWall customers are prepared for any exploitation that may occur due to this vulnerability, the following signature has been released:
| Signature ID | Signature Name |
|---|---|
| IPS 21270 | MLflow Path Traversal 4 |
| IPS 21374 | MLflow Artifacts Information Disclosure |
| IPS 21075 | MLflow Arbitrary File Download |
Share This Article

An Article By
An Article By
Ashwini Bhagwat
Ashwini Bhagwat