SQLAlchemy through version 1.2.17 and versions 1.3.x through 1.3.0b2 is vulnerable to SQL injection through the order_by parameter. Applications that pass attacker-controlled data to this parameter without strict validation may permit manipulation of database queries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit and test environment for CVE-2019-7164, a SQL injection vulnerability in MLflow's search_runs API. The vulnerability allows attackers to inject arbitrary SQL via the order_by parameter, due to insufficient input validation and unsafe use of SQLAlchemy's text() function. The repository provides a Docker-based environment to spin up a vulnerable MLflow instance, along with Python scripts to automate pentest tasks, run tests, and verify patches. The main exploit payload is an order_by parameter that injects SQL, and the environment is designed to help users test, patch, and validate the vulnerability. The structure includes setup scripts, test runners, and a controller module that manages the environment and exposes tools for automated evaluation. The MLflow server is exposed on port 5000, and the vulnerable code paths are clearly identified in the tasks.json file. This is a POC-level exploit environment, not a weaponized attack tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.