Unauthorized Access in Mlflow’s Basic Auth Application
CVE-2025-15381
8.1HIGH
What is CVE-2025-15381?
In the latest versions of Mlflow, when the basic-auth application is enabled, the tracing and assessment endpoints lack adequate permission checks. This flaw allows any authenticated user, even those assigned 'NO_PERMISSIONS' on specific experiments, to access trace metadata and manipulate assessments. As a result, sensitive information can be inadvertently disclosed, compromising confidentiality and permitting unauthorized modification of data, posing serious risks to user privacy and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mlflow/mlflow <= unspecified
