CVE-2024-25723Medium· 6.5▾ TwilightPoC availableZenML Server Remote Privilege Escalation Vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 14.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
71%
71% → 71%
1 GitHub repo · Nuclei ×1
ZenML Server in the ZenML package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.
zenml < 0.42.2zenml >= 0.43.0, < 0.43.1zenml >= 0.45.0, < 0.46.7zenml >= 0.44.0, < 0.44.4Upgrade to a patched release:
zenml 0.42.2zenml 0.43.1zenml 0.46.7zenml 0.44.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-8406Medium· 6.3ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
CVE-2024-4311Medium· 5.4Missing ratelimit on passwrod resets in zenml
CVE-2024-4680Low· 3.9zenml-io/zenml does not expire the session after password reset
CVE-2024-4460Medium· 4.3Improper line feed handling in zenml