{"id":"CVE-2026-96804","published":"2026-09-23T17:17:25.530","lastModified":"2026-09-24T04:18:04.600","description":"MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://kb.cert.org/vuls/id/369093","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a remote attacker to execute arbitrary code by exploiting the MLflow statsmodel flavor's lack of deserialization security control.","exploitability":"Exploitation requires a crafted MLmodel artifact, making it moderately difficult. The attacker must have the ability to deliver and deploy the artifact.","blast_radius":"If exploited, the impact could be severe, as it allows remote code execution, potentially leading to full system compromise.","remediation":"Upgrade to MLflow versions 3.15.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","arbitrary-code-execution","remote","mlflow"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:00:44.613Z"}}