{"id":"CVE-2023-6018","aliases":["GHSA-5p3h-7fwh-92rc","PYSEC-2026-417"],"url":"https://o3.security/vulnerability/CVE-2023-6018","summary":null,"details":"An attacker can overwrite any file on the server hosting MLflow without any authentication.","published":"2024-03-06T10:57:47.076Z","modified":"2026-06-29T12:26:10.661493357Z","cvss":null,"epss":{"score":0.47594,"percentile":0.98791,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Bitnami","name":"mlflow","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://huntr.com/bounties/7cf918b5-43f4-48c0-a371-4d963ce69b30"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T12:26:10.661493357Z"}}