clearml vulnerabilities
CVEs whose affected-version data names the clearml package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2025-8917Medium· 5.8clearml is vulnerable to Path Traversal through its `safe_extract` function
clearml is vulnerable to Path Traversal through its `safe_extract` function
▾ Sunlitclearml · clearmlEPSS 0.30%via OSV
CVE-2024-24591High· 8.8Allegro AI ClearML path traversal vulnerability
Allegro AI ClearML path traversal vulnerability
▾ Twilightclearml · clearmlEPSS 0.80%via OSV
CVE-2024-24595Medium· 6.0Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
▾ Sunlitclearml · clearmlEPSS 0.26%via OSV
CVE-2024-24590High· 8.8PoCAllegro AI ClearML vulnerable to deserialization of untrusted data
Allegro AI ClearML vulnerable to deserialization of untrusted data
▾ Midnightclearml · clearmlEPSS 2.5%via OSV