-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The advisory explicitly identifies the delete_artifacts function in local_artifact_repo.py as the root cause due to an extra unquote operation. This matches the described double decoding mechanism required to exploit the vulnerability. While the _delete_artifact_mlflow_artifacts handler and local_file_uri_to_path are mentioned in the attack chain, the primary code flaw is localized to delete_artifacts's improper sanitization. The confidence is high because the description directly attributes the vulnerability to this function's implementation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| mlflow | pip | <= 2.9.2 |
Ongoing coverage of React2Shell