VYPR

clearml

by allegroai

CVEs (1)

  • CVE-2026-8387LowJul 1, 2026
    risk 0.00cvss 2.4epss 0.00

    A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()` method in `StorageManager._extract_to_cache()`. This issue arises due to the lack of path traversal…