# MLflow versions up to 3.10.1 contain stored XSS and authorization bypass vulnerabilities…

Published: 2026-04-07 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/15c66f3f-e12c-4d0d-b408-764263258cf2/mlflow-versions-up-to-3-10-1-contain-stored-xss-and-authorization-bypass

> MLflow versions up to 3.10.1 contain stored XSS and authorization bypass vulnerabilities allowing artifact theft and session hijacking.

CERT Polska coordinated disclosure of two vulnerabilities in MLflow, an open-source machine learning lifecycle platform. CVE-2026-33865 is a Stored Cross-Site Scripting vulnerability arising from unsafe parsing of YAML-based MLmodel artifacts in the web interface. An authenticated attacker can upload a malicious MLmodel file containing JavaScript payloads that execute when another user views the artifact through the UI, enabling session hijacking or unauthorized actions performed under the victim's context.

CVE-2026-33866 is an authorization bypass vulnerability affecting the AJAX endpoint responsible for downloading saved model artifacts. The endpoint lacks proper access-control validation, allowing users without appropriate permissions to directly query the endpoint and retrieve model artifacts from experiments they should not be able to access. This represents a significant confidentiality breach for organizations using MLflow to manage proprietary machine learning models.

Both vulnerabilities affect all MLflow versions through 3.10.1. Organizations using MLflow should prioritize patching to versions beyond 3.10.1 once available, restrict access to MLflow instances, and review audit logs for unauthorized artifact access or suspicious file uploads.

## Mentioned in this report

- Vulnerabilities: CVE-2026-33865, CVE-2026-33866

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-33865

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/15c66f3f-e12c-4d0d-b408-764263258cf2/mlflow-versions-up-to-3-10-1-contain-stored-xss-and-authorization-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
