vendor

lfprojects

4 thingsrelated by NVD
Severity
Exploited

Its products

mlflow 2 model context protocol servers 2

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849
Severity critical Exploited yes
In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific…
CVE-2025-68145
Severity critical
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git…
CVE-2025-68143
Severity high
mlflow/mlflow: mlflow/mlflow: Information disclosure and unauthorized data modification via unprotected tracing and assessment endpoints
CVE-2025-15381
Severity high