CVE-2025-11201 is a critical directory traversal vulnerability affecting MLflow Tracking Server, allowing unauthenticated remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied file paths, enabling attackers to leverage this to execute code in the context of the service account. With a CVSS score of 9.8 (Critical) and a FAUCET Risk Score of 97/100, this vulnerability poses a significant threat due to its unauthenticated remote code execution capabilities. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community attention with 11 mentions, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025-06-10CPE matchmatch criteria | cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.