Generic PoC for MLflow pickle deserialization RCE (CVE-2024-37054-style). Poisons a registered model via the MLflow REST API to achieve code execution when the model is loaded.
python exploit poc rce pentest redteam machine-learning-security mlflow pickle-deserialization mlops-security cve-2024-37054
-
Updated
Sep 23, 2026 - Python