logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-27132

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-27132

Description:
Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables.
Last updated date:
01/22/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/22/2025
Reference url to background

https://research.jfrog.com/vulnerabilities/mlflow-untrusted-recipe-xss-jfsa-2024-000631930/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy