CVE-2023-6940 is a critical command injection vulnerability (CWE-77) affecting lfprojects mlflow, allowing attackers to achieve full command execution on a victim system. This high-severity flaw (CVSS 8.8) requires only a single user interaction, specifically downloading a malicious configuration file, making it a low-complexity attack with high impact on confidentiality, integrity, and availability. While not currently in the KEV catalog or actively exploited, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.9.2CPE matchmatch criteria | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.