Record summary

CVE-2025-15379 has a selected CVSS score of 9.8 (critical).

Description

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` file and directly interpolates them into a shell command without sanitization. This allows an attacker to supply a malicious model artifact and achieve arbitrary command execution on systems that deploy the model. The vulnerability affects versions 3.8.0 and is fixed in version 3.8.2.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 31, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-training-cuda128-torch29-py312-rhel9

Default status: affected

CVE ListVersion data not supplied
CVE ListBefore 3.8.2affected
GitHub AdvisoryBefore 3.8.1 · Fixed in 3.8.1affected

References

8