VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control https:// kb.cert.org/vuls/id/369093 Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows
VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control https:// kb.cert.org/vuls/id/369093 Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels f