Skip to content

[GHSA-5p3h-7fwh-92rc] Remote Code Execution due to Full Controled File Write in mlflow - #9620

Open
nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9620from
nikpivkin-GHSA-5p3h-7fwh-92rc
Open

nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9620from
nikpivkin-GHSA-5p3h-7fwh-92rc

Conversation

@nikpivkin

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The first patched version should be 2.9.0, not 2.9.2.

The fix commit linked in the advisory is mlflow/mlflow@55c72d0 (#10585). Tag v2.9.0 contains it and tag v2.8.1 does not. The 2.9.0 release notes list #10585 under "Security fixes": https://github.com/mlflow/mlflow/releases/tag/v2.9.0

The other two security fixes from those notes already have their own advisories with 2.9.0 as the patched version: #10584 is CVE-2024-0520 (GHSA-5q6c-ffvg-xcm9) and #10526 is CVE-2023-6568 (GHSA-vwhf-3v6x-wff8). The path traversal fixes in 2.9.2 also have their own CVEs and commits, for example CVE-2023-6975, CVE-2023-6976 and CVE-2023-6909.

The OSV export takes the fixed version from the first patched version, so versions 2.9.0 and 2.9.1 are reported as vulnerable even though they have the fix.

Copilot AI balanced review requested due to automatic review settings September 19, 2026 13:10
@github-actions
github-actions Bot changed the base branch from main to nikpivkin/advisory-improvement-9620 September 19, 2026 13:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The 2.9.0 release notes identify the linked fix as a security patch, and the advisory metadata remains internally consistent.

Review effort: Balanced
Findings: None

What changed in this PR

Corrects the mlflow advisory’s first patched version so OSV exports no longer mark fixed releases as vulnerable.

Changes:

  • Changes the fixed version from 2.9.2 to 2.9.0.
  • Updates the advisory modification timestamp.
File Description
advisories/​github-reviewed/​2023/​11/​GHSA-5p3h-7fwh-92rc/​GHSA-5p3h-7fwh-92rc.json Corrects the affected-version range.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants