VYPR

clearml

by allegroai

CVEs (2)

  • CVE-2024-24592CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.

  • CVE-2026-8387LowJul 1, 2026
    risk 0.00cvss 2.4epss 0.01

    A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()` method in `StorageManager._extract_to_cache()`. This issue arises due to the lack of path traversal…