Critical severity9.9NVD Advisory· Published Feb 6, 2024· Updated Jun 17, 2026
CVE-2024-24594
CVE-2024-24594
Description
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Allegro.AI/ClearMLv5Range: 0
Patches
Vulnerability mechanics
References
1- hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.