Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook.
The vulnerability stems from lack of sanitization over template variables.
"https://github.com/pypa/advisory-database/blob/main/vulns/mlflow/PYSEC-2024-240.yaml"