CVE-2025-1473
HIGHMLflow 2.17.0-2.20.1 - Cross-Site Request Forgery in Signup Feature
Title source: llmDescription
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/43dc50b6-7d1e-41b9-9f97-f28809df1d45
Scores
CVSS v3
7.1
EPSS
0.0016
EPSS Percentile
36.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (2)
lfprojects/mlflow
2.17.0 - 2.20.1
pypi/mlflow
2.17.0 - 2.20.3PyPI
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026