CVE-2025-15381
In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.
- Affected products
- Mlflow
- Lfprojects Mlflow
- All versions
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.3% (26th percentile)
- Weakness
- CWE-200, CWE-425
- NVD status
- Modified
- Published
- 2026-03-27
No indexed exploits for CVE-2025-15381 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-15381 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.