Opening SecureFlowMLflow Unauthenticated Webhook Redirect to Full-Read SSRF
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MLflow aidefend-sf0029

MLflow Unauthenticated Webhook Redirect to Full-Read SSRF

  • AI Infrastructure
  • Credential & Identity Theft
  • Data Exfiltration

On a default MLflow Tracking Server through 3.13.0, unauthenticated webhook APIs accept a public HTTPS URL. Delivery follows a 302 without revalidating or pinning the redirect target, and the synchronous test endpoint returns the internal response body.

Mapped threat techniques

  • AML.T0049 Exploit Public-Facing Application
  • AML.T0107 Exploitation for Defense Evasion
  • AML.T0025 Exfiltration via Cyber Means

Source

Updated