THREAT OPS › Threat News › [GHSA] GHSA-gqch-g4w5-7qcw (high) — MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
[GHSA] GHSA-gqch-g4w5-7qcw (high) — MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
GHSA-gqch-g4w5-7qcw Severity: high CVE: CVE-2026-69148
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
### Summary
The `_validate_source_run` and `_validate_source_model` functions in `mlflow/server/handlers.py` verify that a model version source path is within the artifact directory of a specified run or logged model, but do not check whether th
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-69148cve
- run.infodomain
Original source: https://github.com/advisories/GHSA-gqch-g4w5-7qcw