VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control https:// kb.cert.org/vuls/id/369093 Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control https:// kb.cert.org/vuls/id/369093 Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels f

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control https:// kb.cert.org/vuls/id/369093 Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows

mastodon:infosec-exchangeother13d ago kagi ↗

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control https:// kb.cert.org/vuls/id/369093 Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels f