Most recent
navigate open esc close Corpus index built 2026-06-07 23:58 UTC

§ THE STACK / DATA LAYER

MLOps Tracking

MLflow, W&B, ClearML, Aim, Comet ML. experiment tracking + model registry

Vector stores, registries, memory, datasets: what the model knows and remembers.

What it is

When you train models for a living you need to track every experiment: hyperparameters, metrics, artefacts, the model file itself. MLflow (Databricks) is the open default; Weights & Biases is the polished SaaS incumbent; Kubeflow Pipelines, Metaflow (Netflix), and Comet sit in the same niche. The tracking server is the operator’s training history, their model registry, and increasingly the artefact store from which production deployments pull.

What goes wrong

MLflow has no native authentication. The maintainers’ guidance is to deploy behind a reverse proxy. Most operators don’t, and the consequences are richer than they look. CVE-2023-1177 turns the artefact-fetch endpoint into a path-traversal RCE: an attacker creates an experiment with a crafted artefact URI and reads any file the MLflow process can read. We have found instances where this CVE was actively being exploited by other parties: the attacker’s experiment runs were sitting alongside the operator’s, with names like “recon”, “shell”, “check”. The operator’s model files, training data paths, and cloud-credential filenames all leak in the same way.

How we test

We probe /api/2.0/mlflow/experiments/search for the experiment inventory and /api/2.0/mlflow/runs/search for run-level metadata. We do not invoke the artefact-fetch endpoint. Operator attribution comes from the experiment names, the model architecture (visible in the params), and frequently the dataset URIs which point at named S3 buckets. Where we see signs of third-party exploitation we escalate the disclosure with the threat-actor evidence included.

Receipts

Research

Every survey, case study, and disclosure we've published that touches this layer of the stack. Counts on the cells above tally these directly.

Cross-cloud surveys

10
Survey May 29, 2026

Experiment Tracking, registry and RCE half, 2026-05-29

MLflow ships with no authentication, and the population shows it: eight of eight sampled servers returned the full experiment list with no credentials. One held 379 experiments and leaked a Google Clo…

Read →
Survey May 27, 2026

ML Governance / Data Catalog Survey — OpenMetadata + DataHub

56 confirmed governance platforms, 56 auth-enforced. Zero auth-off. All OpenMetadata instances run v1.3.1+, past the CVE-2024-28255 patch boundary. Version disclosure MEDIUM on 31 OpenMetadata hosts.

Read →
Survey May 17, 2026

Training observability survey, 2026-05-17

We surveyed self-hosted training-observability platforms: Weights & Biases (self-hosted), ClearML, Aim, Ray Dashboard, MLflow. The aim was to map the population of public-facing experiment trackers an…

Read →
Survey May 16, 2026

Experiment-Tracking Population Survey (2026-05-16)

Closes the experiment-tracking half of category 04 (the compute-orchestration half was surveyed 2026-05-06 with Spark / Airflow / Ray). MLflow was surveyed earlier in the series (Insight #18 buckets-l…

Read →
Survey May 13, 2026

VisorBishop Phase 5b: Bucket-accessibility pass against 49 MLflow artifact stores

NuClide Research · 2026-05-13

Read →
Survey May 13, 2026

VisorBishop Phase 5b: bucket-accessibility pass against 49 MLflow artifact stores (public)

NuClide Research · 2026-05-13

Read →
Survey May 11, 2026

VisorBishop iter-4: Adjacent platforms (Opik, AgentOps, Phospho)

NuClide Research · 2026-05-11

Read →
Survey May 11, 2026

VisorBishop iter-7: MLflow Tracking + Weights & Biases self-host (experiment-tracking tier)

NuClide Research · 2026-05-11

Read →
Survey May 11, 2026

VisorBishop iter-8: Six platforms swept, near-zero critical (LLM pipeline + ML orchestration + product analytics)

NuClide Research · 2026-05-11

Read →
Survey May 3, 2026

MLflow Tracking Server on Public Cloud: Auth Posture Survey

Mass-scan of port 5000 across 28 cloud-provider /16 ranges (DO/Hetzner/Vultr) returned 12,106 hits → fingerprinted via /version + /api/2.0/mlflow/experiments/search body match → 11 confirmed MLflow Tr…

Read →

Coordinated disclosures

15
May 17, 2026

Aussie Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Aws Clearml Signup Open Batch 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Azure Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Gcp Clearml Signup Open Batch 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Hetzner Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

In Adya Ai Vanijmcp Wandb Proxy 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Ovh Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Pti Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Scaleway Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
May 17, 2026

Teithe Clearml Signup Open 2026 05 17

Nicholas Michael Kloster / NuClide Research nicholas@nuclide-research.com

Read →
CRITICAL May 13, 2026

Salutegroup Smartshop Ai Amazonrec 2026 05 13

Salute Group, SmartShop AI / amazonrec.space full MLOps pipeline exposed on PENTECH BILISIM host

Read →
HIGH sent May 6, 2026

Digitalocean 138 197 152 103 Aipod Mlflow

DigitalOcean, orthodontic-AI startup ("AIPOD") MLflow 2.2.1 actively exploited via CVE-2023-1177; 3-year persistent exposure

Read →
HIGH sent May 6, 2026

1. Patch MLflow immediately - upgrade to 2.10.0+ (CVE-2023-1177 patched in 2.3.1).

DigitalOcean, Squeeze/Helios short-squeeze trading platform; MLflow 2.9.2 actively exploited (CVE-2023-1177) + Vault dev-mode + Prometheus full architecture leak

Read →
CRITICAL sent May 6, 2026

1. CLAIM THE METABASE SETUP-TOKEN IMMEDIATELY.

Hetzner DE, pediatric medical ML operator with 224 unauth MLflow experiments + Metabase setup-token unclaimed (pre-auth admin takeover)

Read →
CRITICAL sent May 6, 2026

Hetzner 65 109 36 121 Wellcalf Correction

Hetzner DE, CORRECTION to prior disclosure; operator is WellCalf ML (livestock / veterinary AI, NOT pediatric medical)

Read →