lfprojects
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 99 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 23, 2022 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Improper Origin Validation in mlflow/mlflow
Authentication Bypass in mlflow/mlflow
MCP Registry: Unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
MCP Registry: GitHub OIDC tokens replayable across registry deployments due to shared audience
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
MCP Java-SDK has a DNS Rebinding Vulnerability
Authorization Bypass in MLflow AJAX Endpoint
Stored XSS via unsafe YAML parsing in MLflow
Missing Authentication for Critical Function in mlflow/mlflow
Monitor lfprojects in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.