{"id":"CVE-2024-24591","aliases":["GHSA-m95h-p4gg-wfw3","PYSEC-2026-1258"],"title":"Allegro AI ClearML path traversal vulnerability","summary":"Allegro AI ClearML path traversal vulnerability","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"clearml","product":"clearml","ecosystem":"pip","affected":["clearml >= 0.17.0, <= 1.14.1"],"published":"2024-02-06","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-m95h-p4gg-wfw3","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24591"},{"url":"https://github.com/allegroai/clearml"},{"url":"https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain"}],"tags":["osv","pip"],"epss":0.00798,"epssPercentile":0.54994,"ingestedAt":"2026-07-08T18:25:51.189Z","slug":"CVE-2024-24591","body":"## Overview\n\nA path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.\n\n## Affected packages\n\n- `clearml >= 0.17.0, <= 1.14.1`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}