logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-37059

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-37059

Description:
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.
Last updated date:
02/03/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/03/2025
Reference url to background

https://hiddenlayer.com/sai-security-advisory/mlflow-june2024

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy