Remote Code Execution Vulnerability in MLflow dspy Flavor by Databricks
CVE-2026-96775
8.8HIGH
What is CVE-2026-96775?
Databricks MLflow's dspy flavor, starting from version 2.0, presents a vulnerability due to improper application of the MLFLOW_ALLOW_PICKLE_DESERIALIZATION security control. This control is enforced only when the model_path ends with .pkl. Consequently, this oversight can be exploited by remote attackers to execute arbitrary code through crafted MLmodel artifacts, posing significant risks to the integrity and confidentiality of affected systems.
Affected Version(s)
MLflow 2.0
