A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the --serve-artifacts mode is enabled. The authorization logic does not enforce resource-level permission checks for /mlflow-artifacts/mpu/* endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.
{
"cwe_ids": [
"CWE-1220",
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-30T16:48:21Z",
"nvd_published_at": "2026-05-25T07:16:15Z",
"severity": "CRITICAL"
}