An unauthenticated endpoint in MLflow’s webhook tester can be redirected to internal addresses or cloud metadata services, and the response body is handed straight back to the attacker.