Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

CERT Coordination Center Version 1 original

Imported from official source

Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Description MLflow is an open-source platform for managing machine learning lifecycles, including model packaging, versioning, and deployment. "Flavors" refer to the specialized frameworks through which supported models are stored and loaded. In response to previous vulnerability con...

This version

Version
1 of 4
Recorded
September 16, 2026 17:30
Change
Initial
Content hash
1a6164a7f20ef82b48d4be97a35ac53b
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.