{"id":"CVE-2025-1473","aliases":["BIT-mlflow-2025-1473","GHSA-969w-gqqr-g6j3","PYSEC-2026-1646"],"url":"https://o3.security/vulnerability/CVE-2025-1473","summary":"CSRF in mlflow/mlflow","details":"A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.","published":"2025-03-20T10:10:20.747Z","modified":"2026-08-12T15:13:38.147548Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mlflow","fixedVersion":"2.20.3"}],"fix":{"url":"https://github.com/mlflow/mlflow/commit/ecfa61cb43d3303589f3b5834fd95991c9706628","label":"mlflow/mlflow@ecfa61c"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/43dc50b6-7d1e-41b9-9f97-f28809df1d45"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1473.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1473"},{"type":"FIX","url":"https://github.com/mlflow/mlflow/commit/ecfa61cb43d3303589f3b5834fd95991c9706628"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:13:38.147548Z"}}