Skip to content
ZenMLGHSA-9x88-4jg8-4vf7

Improper authorization in zenml

Medium6.5CVE-2024-2035 · Published Jun 6, 2024 · updated Oct 16, 2025

An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the `active` status of user accounts to false, effectively deactivating them. This issue affects version 0.55.3 and was fixed in version 0.56.2. The impact of this vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting the functionality and security of the application.

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
< 0.56.20.56.2
Details and references

More ZenML advisories

All ZenML
Advisory
Improper line feed handling in zenml
Medium4.3Jun 24, 2024
zenml-io/zenml does not expire the session after password reset
Low3.9Jun 8, 2024
Race condition in zenml
Low3.1Jun 6, 2024
Improper authentication in zenml
Low3.3Jun 6, 2024
Clickjacking in zenml
Medium4.3Jun 6, 2024
Cross site scripting in zenml
Low3.4Jun 6, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.