GHSA-j46q-5pxx-8vmw · Severity: high · Ecosystem: pip — Local File Inclusion in mlflow
A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system, including sensitive files like '/etc/passwd'. The vulnerability is a bypass to a previous patch that only addressed similar manipulation within the URI's query string, highlighting the need for comprehensive validation of all parts of a URI to prevent LFI attacks.
Conclusion & alert: CVE-2024-2928 is rated High Exploit Risk (79.5/100): CVSS High severity, with high exploitation likelihood (EPSS 91.16%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-10 | 91.55% | 91.16% | -0.39% |
| 2 | 2026-02-08 | 91.42% | 91.55% | +0.13% |
| 3 | 2026-01-30 | — | 91.42% | — |
Full EPSS history (34 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-j46q-5pxx-8vmw · Severity: high · Ecosystem: pip — Local File Inclusion in mlflow
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lfprojects | mlflow | < 2.11.3 | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/mlflow/mlflow/commit/96f0b573a73d8eedd6735a2ce26e08859527be07 | Patch |
| https://huntr.com/bounties/19bf02d7-6393-4a95-b9d0-d6d4d2d8c298 | Exploit Issue Tracking Patch Third Party Advisory |