with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
"https://github.com/pypa/advisory-database/blob/main/vulns/mlflow/PYSEC-2026-1652.yaml"