Vulnerability Details CVE-2025-10279
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtual environment, leading to arbitrary code execution. The issue is resolved in version 3.4.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.6%
CVSS Severity
CVSS v3 Score 7.0
Products affected by CVE-2025-10279
-
cpe:2.3:a:lfprojects:mlflow:2.0.0
-
cpe:2.3:a:lfprojects:mlflow:2.15.0
-
cpe:2.3:a:lfprojects:mlflow:2.17.0
-
cpe:2.3:a:lfprojects:mlflow:2.18.0
-
cpe:2.3:a:lfprojects:mlflow:2.19.0
-
cpe:2.3:a:lfprojects:mlflow:2.20.0
-
cpe:2.3:a:lfprojects:mlflow:2.21.0
-
cpe:2.3:a:lfprojects:mlflow:2.22.0
-
cpe:2.3:a:lfprojects:mlflow:3.0.0
-
cpe:2.3:a:lfprojects:mlflow:3.1.0
-
cpe:2.3:a:lfprojects:mlflow:3.2.0
-
cpe:2.3:a:lfprojects:mlflow:3.3.0