OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-96775 (CVSS 8.8)

NVD · officialPublished Sep 23, 2026Risk 37/100EPSS 0.4%

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source