Skip to content
ZenMLGHSA-3434-hc3m-8mmm

Reflected Cross-Site Scripting (XSS) in zenml

Medium6.1CVE-2024-5062 · Published Jun 30, 2024 · updated Jan 21, 2025

A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, specifically within the survey redirect parameter. This flaw allows an attacker to redirect users to a specified URL after completing a survey, without proper validation of the 'redirect' parameter. Consequently, an attacker can execute arbitrary JavaScript code in the context of the user's browser session. This vulnerability could be exploited to steal cookies, potentially leading to account takeover.

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
>= 0.57.1, < 0.58.00.58.0
Details and references

More ZenML advisories

All ZenML
Advisory
Improper line feed handling in zenml
Medium4.3Jun 24, 2024
zenml-io/zenml does not expire the session after password reset
Low3.9Jun 8, 2024
Improper authorization in zenml
Medium6.5Jun 6, 2024
Race condition in zenml
Low3.1Jun 6, 2024
Improper authentication in zenml
Low3.3Jun 6, 2024
Clickjacking in zenml
Medium4.3Jun 6, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.