Security & Best Practices
Last updated on
Handling MLflow™ Model Artifacts (CVE-2026-79721)
Section titled “Handling MLflow™ Model Artifacts (CVE-2026-79721)”MLflow™ intentionally supports custom Python code execution as a core feature for specific model types to allow developers to package custom logic like data preprocessing.
In our service architecture, the managed tracking server directly handles only metadata, while the actual model artifact files are uploaded, retrieved, and stored directly by your client into your own Object Storage using your S3 credentials.
Because these file transfers occur strictly between your client application and your storage bucket, our platform cannot inspect, filter, or restrict the content uploaded to your storage.
Under the security vulnerability disclosed in CVE-2026-79721, loading a malicious MLflow™ model artifact (for example with mlflow.pyfunc.load_model()) causes custom Python code to execute immediately in the host environment during the loading step itself, rather than waiting for model execution.
Consequently, because simply loading an artifact into memory can run embedded code, you must treat loading any MLflow™ model artifact with the exact same caution as executing an arbitrary script on your host system.
Recommended Actions:
-
Do Not upload untrusted files: Avoid uploading untrusted artifacts or third-party models to your Object Storage buckets, as loading them downstream can expose your execution environment to malicious code.
-
Load only from trusted sources: Never download or load artifacts, model registry references, or runs originating from unverified external sources or untrusted users.
-
Restrict write access: Review bucket permissions and user roles to ensure untrusted users cannot upload, replace, or modify model artifacts or registry references.
-
Isolate untrusted models: Treat all model artifacts as executable scripts. Evaluate or inspect unverified models strictly inside isolated sandbox environments.
-
Apply least privilege: Ensure applications, pipelines, and services that load models run with minimal necessary permissions.