CVE-2025-15381
Last modified
CVE-2025-15381 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lfprojects | Mlflow | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-15381?
How severe is CVE-2025-15381?
How do I fix CVE-2025-15381?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-15376The Stopwords for comments plugin for WordPress is vulnerabl…4.3
- CVE-2025-15377The Sosh Share Buttons plugin for WordPress is vulnerable to…4.3
- CVE-2025-15378The AJS Footnotes plugin for WordPress is vulnerable to Stor…7.2
- CVE-2025-15379A command injection vulnerability exists in MLflow's model s…9.8
- CVE-2025-1538A vulnerability classified as critical was found in D-Link D…8.8
- CVE-2025-15380The NotificationX – FOMO, Live Sales Notification, WooCommer…7.2
- CVE-2025-15382A heap buffer over-read vulnerability exists in the wolfSSH_…8.1
- CVE-2025-15385Insufficient Verification of Data Authenticity vulnerability…9.8
- CVE-2025-15386The Responsive Lightbox & Gallery WordPress plugin before 2.…8.8
- CVE-2025-15387VPN Firewall developed by QNO Technology has a Insufficient …8.8
- CVE-2025-15388VPN Firewall developed by QNO Technology has an OS Command I…8.8
- CVE-2025-15389VPN Firewall developed by QNO Technology has an OS Command I…8.8
Are you affected by CVE-2025-15381?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
