CVE-2026-96775
Beschrijving NL
De dspy-smaak van MLflow, versies >= 2.0, past de MLFLOW_ALLOW_PICKLE_deserialization =Valse beveiligingscontrole alleen toe wanneer het model_Path eindigt op .pkl, waardoor een externe aanvaller willekeurige code kan uitvoeren via een vervaardigd MLmodel-artefact.
Origineel (Engels) tonen
MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.