{"id":"CVE-2026-96775","published":"2026-09-23T17:17:25.407","lastModified":"2026-09-23T18:17:12.323","description":"MLflow's dspy flavor, versions >= 2.0,  applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://kb.cert.org/vuls/id/369093","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a remote attacker to execute arbitrary code by crafting a specific MLmodel artifact, due to the lack of proper deserialization security control.","exploitability":"Exploitation is moderately hard as it requires crafting a specific MLmodel artifact, but preconditions include having access to the model_path.","blast_radius":"If exploited, the impact is high, as it could lead to complete system compromise and execution of arbitrary code on the server.","remediation":"Upgrade to MLflow version 2.0.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","arbitrary-code-execution","mlflow","security-control"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:56:59.981Z"}}