lfprojects
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting lfprojects.
- CVE-2026-59950MCP Python SDK: WebSocket server transport does not support Host/Origin validation8.1
- CVE-2026-52870MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks7.6
- CVE-2026-52869MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal7.1
- CVE-2026-8147Authorization Bypass in mlflow/mlflow8.1
- CVE-2026-13484MLflow Experiment-scoped Label Schema CRUD API authorization5.0
- CVE-2026-10803MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash3.6
- CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow7.7
- CVE-2026-3198Improper Access Control in mlflow/mlflow6.5
- CVE-2026-2651Missing Authorization Validation in mlflow/mlflow9.0
- CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow6.5
- CVE-2026-2611Improper Origin Validation in mlflow/mlflow9.6
- CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow7.8
- CVE-2026-2652Authentication Bypass in mlflow/mlflow8.6
- CVE-2026-44428MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience4.7
- CVE-2026-44429MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`5.4