VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control
Cybersecurity Classified by Officially
Two vulnerabilities in MLflow’s dspy and statsmodels model flavors allow unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control.
MLflow is an open-source platform for managing machine learning lifecycles, including model packaging, versioning, and deployment. "Flavors" refer to the specialized frameworks through which supported models are stored and loaded. In response to previous vulnerability concerns, MLflow implemented the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control to block and disable executing any pickle deserialization and subsequent loads per the user’s choice.
When loading models through mlflow.pyfunc.load_model(model), users must specify a model flavor and path in an MLmodel file. With the dspy flavor, MLflow checks the value of MLFLOW_ALLOW_PICKLE_DESERIALIZATION, and whether the specified model path ends in .pkl. A model path that does not end in .pkl (even if the file is actually a pickle file), will route to a separate branch for pickle deserialization, bypassing the safety control. However, when loading through the statsmodels flavor, there is no check for MLFLOW_ALLOW_PICKLE_DESERIALIZATION at all.
These vulnerabilities are tracked as CVE-2026-96804 and CVE-2026-96775, respectively.
Exploitation of these vulnerabilities allow for arbitrary remote code execution through a malicious pickle-loaded payload, regardless of a user explicitly disallowing pickle serialization, through vulnerable flavor specifications in the MLmodel configuration file. The attack path requires write access to any location from which a user obtains MLflow models. This vulnerability was confirmed against MLflow 3.12.0.
This is an extract. The publication continues at the source.
Read the original at the source: https://kb.cert.org/vuls/id/369093
Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
4 versions recorded. The original is kept in full — nothing is overwritten.
- v4 imported change on current
- v3 imported change on
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- CERT Coordination Center — imported from official source
- Official source
- https://www.kb.cert.org/vuls/atomfeed/ ATOM
- Imported
- September 16, 2026 17:30
- Versions
- 4 recorded
- Identity
https://kb.cert.org/vuls/id/369093