CVE-2026-0596 is a command injection vulnerability in mlflow/mlflow that occurs when serving a model with enable_mlserver=True. In the vulnerable code path, the model_uri value is incorporated directly into a shell command executed via bash -c without proper sanitization or safe argument handling. Because model_uri is attacker-controllable in relevant deployment scenarios, shell metacharacters such as $() or backticks can be injected to trigger command substitution, resulting in execution of attacker-supplied commands in the context of the MLflow serving process. The issue is reported as affecting the latest version of MLflow.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
enable_mlserver=True in untrusted or mixed-trust environments. Do not allow untrusted users to control or modify model_uri values or write to directories from which privileged MLflow services load or serve models. Run MLflow serving processes with the least privileges possible, isolate them from sensitive hosts and data, and apply filesystem permissions so lower-privileged users cannot influence model artifacts consumed by higher-privileged services. Additional hardening includes disabling shell-based execution paths where possible and constraining the service with containerization, MAC policies, or similar sandboxing controls.Patch, then assume compromise.
model_uri must not be interpolated into commands executed through bash -c; instead, invoke subprocesses without a shell and pass arguments as a structured argument vector, with strict validation and normalization of model_uri. Review MLflow model-serving configurations using enable_mlserver=True, especially where model sources are writable by less-trusted users, and restrict those trust boundaries until a fix is deployed.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python/Docker proof-of-concept lab for insecure deserialization in the MLflow ecosystem, centered on claimed CVE-2026-0596. It contains 8 files: container setup (Dockerfile, docker-compose.yml), documentation (README.md), dependency pinning (requirements.txt), and three Python scripts. The core exploit logic is in trigger_native.py, which defines an ExploitModel class whose __reduce__ method returns os.system with a shell command. When the generated pickle file vulnerable_model.pkl is loaded with pickle.load(), the command executes immediately, creating /tmp/native_success_marker.txt. This demonstrates arbitrary code execution via unsafe deserialization of attacker-controlled pickle content. Repository structure and purpose: generate_model.py creates a minimal MLflow pyfunc model under /app/saved_model for use in the containerized lab. docker-compose.yml starts an MLflow serving instance with mlflow models serve -m /app/saved_model --host 0.0.0.0 --port 5000 --no-conda --enable-mlserver. verify_poc.py sends a POST request to http://localhost:5000/invocations with a JSON payload attempting shell metacharacter injection through params.custom_runtime_param; based on both the README and the code comments, this path is not the successful exploit path and serves more as a negative test showing that direct API parameter injection is handled as a string literal. The README explains this distinction clearly: command injection via request parameters fails, while deserialization of malicious pickle artifacts succeeds. Main exploit capability: local or application-mediated arbitrary command execution during model/artifact loading. The exploit does not include a reverse shell or staged payload; it uses a hardcoded command to create a marker file, so the maturity is best described as OPERATIONAL rather than weaponized. Fingerprintable targets/endpoints include the MLflow inference endpoint /invocations on localhost:5000, the served model path /app/saved_model, the malicious artifact vulnerable_model.pkl, and the marker files under /tmp. Overall, this is a genuine exploit PoC repository demonstrating insecure deserialization rather than a pure detection script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command injection vulnerability in MLflow described in the content as enabling privilege escalation via model serving.
A command injection vulnerability in mlflow/mlflow when serving a model with enable_mlserver=True, caused by unsanitized embedding of model_uri into a bash -c shell command, enabling attacker-controlled command execution and possible privilege escalation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.