ClearMLGHSA-579p-qf78-fqm2
clearml is vulnerable to Path Traversal through its `safe_extract` function
Medium5.8CVE-2025-8917 · Published Oct 5, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| clearml PyPI | < 2.0.2 | 2.0.2 |
Details and references
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2025-8917, PYSEC-2026-1255
More ClearML advisories
All ClearML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 62024 | Allegro AI ClearML path traversal vulnerability CVE-2024-24591High8.8no fix yet | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML vulnerable to deserialization of untrusted data CVE-2024-24590High8.8no fix yet | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance CVE-2024-24595Medium6.0no fix yet | Medium6.0 | No fix yet |