CVE detail
CVE-2025-10279 — CVE-2025-10279
Published 2026-02-02 · Modified 2026-06-17 · Vendor lfprojects · Product mlflow · Source nvd
HIGH
severity
CVSS-derived band
0.0022
EPSS probability
exploitation probability, 30d
12.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite `.py` files in the virtual environment, leading to arbitrary code execution. The issue is resolved in version 3.4.0.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References