lfprojects security advisories
2 threat alerts tracking vulnerabilities and security advisories that affect lfprojects products.
Vulnios monitors lfprojects CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent lfprojects security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-15379 — lfprojects — mlflow
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_
criticalCVE-2025-15379Critical Vulnerability: CVE-2025-68145 — lfprojects — model_context_protocol_servers
In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments
criticalCVE-2025-68145
Track lfprojects exposure across your environment
Vulnios automatically cross-references your asset inventory against new lfprojects CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan