Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HSummary
CVE-2023-3765 is a critical-severity Absolute Path Traversal (CWE-36) vulnerability in Lfprojects Mlflow. Its CVSS base score is 10.0 (Critical).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 0.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2023-3765 is an absolute path traversal vulnerability, tracked as CWE-36, that affects the MLflow machine-learning platform in the GitHub repository mlflow/mlflow prior to version 2.5.0. The flaw received a CVSS 3.1 base score of 10.0, reflecting network attack vector, low attack complexity, no required privileges or user interaction, and changed scope that can produce total loss of confidentiality, integrity, and availability.
An unauthenticated attacker reachable over the network can supply crafted paths that escape intended directories, enabling arbitrary file read or write operations on the server hosting the MLflow instance and potentially leading to full system compromise.
The referenced GitHub commit 6dde93758d42455cb90ef324407919ed67668b9b and the associated huntr.dev report indicate that the issue is resolved by upgrading to MLflow 2.5.0 or later. The EPSS score has reached a peak of 0.9279 with a current value of 0.9145, and the affected component is widely used in machine-learning workflows.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-2050
Vulnerability Data
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require input validation and path sanitization that prevent absolute path traversal.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect absolute path traversal via static analysis and fuzzing.
Secure development lifecycle includes input validation and path-handling requirements that reduce absolute path traversal risk.
Application security requirements typically mandate controls against path traversal in file-access functions.
Secure architecture principles call for canonicalization and sandboxing that limit absolute path traversal.
Secure coding standards directly require neutralization of absolute path sequences in pathname construction.
Information access restriction limits which files can be reached but does not address the path-construction flaw itself.