ClearMLGHSA-cpcw-9h9m-wqw9
Allegro AI ClearML vulnerable to deserialization of untrusted data
High8.8CVE-2024-24590 · Published Feb 6, 2024 · updated Jul 7, 2026
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| clearml PyPI | >= 0.17.0, <= 1.14.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2024-24590, PYSEC-2026-1256
More ClearML advisories
All ClearML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 52025 | clearml is vulnerable to Path Traversal through its `safe_extract` function | Medium5.8 | 2.0.2 |
| Feb 62024 | Allegro AI ClearML path traversal vulnerability | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance | Medium6.0 | No fix yet |