CVE-2025-8406Medium· 6.3▾ SunlitZenML is vulnerable to Path Traversal through its `PathMaterializer` class
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
ZenML version 0.83.1 is affected by a path traversal vulnerability in the PathMaterializer class. The load function uses is_path_within_directory to validate files during data.tar.gz extraction, which fails to effectively detect symbolic and hard links. This vulnerability can lead to arbitrary file writes, potentially resulting in arbitrary command execution if critical files are overwritten.
zenml >= 0.81.0, < 0.84.2Upgrade to a patched release:
zenml 0.84.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-25723Medium· 6.5ZenML Server Remote Privilege Escalation Vulnerability
CVE-2024-4311Medium· 5.4Missing ratelimit on passwrod resets in zenml
CVE-2024-4680Low· 3.9zenml-io/zenml does not expire the session after password reset
CVE-2024-4460Medium· 4.3Improper line feed handling in zenml