CVE-2023-6940: Lfprojects MLflow
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
Affected products
- Lfprojects MLflow: before 2.9.2 (fixed in 2.9.2)
Published 2023-12-19. Last modified 2026-06-17.