# MLflow XSS and authz bypass affect versions through 3.10.1

Published: 2026-04-07 · Severity: medium
Canonical: https://vorant.io/reports/2a52315e-c7f9-55c4-91ae-71457849f608/mlflow-xss-and-authz-bypass-affect-versions-through-3-10-1

> MLflow versions through 3.10.1 contain a stored XSS flaw via malicious YAML artifacts and an authorization bypass allowing unauthorized model artifact downloads.

CERT Polska coordinated the disclosure of two vulnerabilities in MLflow, an open-source machine learning lifecycle platform. CVE-2026-33865 is a stored cross-site scripting vulnerability caused by unsafe parsing of YAML-based MLmodel artifacts in the web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI, enabling session hijacking or performing operations on behalf of the victim.

CVE-2026-33866 is an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access-control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. Both vulnerabilities affect MLflow versions through 3.10.1.

The vulnerabilities were responsibly disclosed by Sławomir Zakrzewski of AFINE and coordinated through CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2026-33865, CVE-2026-33866

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-33865

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2a52315e-c7f9-55c4-91ae-71457849f608/mlflow-xss-and-authz-bypass-affect-versions-through-3-10-1.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
