PYPI · MAY 2026 · EARLY WARNING

MLflow <=3.10.1.dev0 Vulnerability: Unauthorized Access Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-8C7Q-86FQ-VVMHSeverity: HIGH

An early warning has been issued regarding a vulnerability in MLflow versions <=3.10.1.dev0 that reportedly allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled. This issue appears to enable unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded.

What happened

According to the GitHub Advisory Database, MLflow versions <=3.10.1.dev0 are under investigation for a severe vulnerability tracked as GHSA-8C7Q-86FQ-VVMH. When the `--serve-artifacts` mode is enabled, unauthorized users may gain access to multipart upload endpoints. This could potentially lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution if compromised models are subsequently loaded.

Professional software engineers using MLflow should assess their exposure by checking if they are running a version <=3.10.1.dev0 and if the `--serve-artifacts` mode is enabled in their configurations. It is recommended to upgrade to MLflow version 3.10.0 or later as a precautionary measure. Further details and confirmations should be obtained from the primary sources, specifically the GitHub Advisory Database entry for GHSA-8C7Q-86FQ-VVMH.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If mlflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats