ClearMLGHSA-gvqv-h7hh-6fcc
Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
Medium6.0CVE-2024-24595 · Published Feb 6, 2024 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| clearml PyPI | <= 1.14.2 | No fix yet |
Details and references
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
More ClearML advisories
All ClearML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 62024 | Allegro AI ClearML vulnerable to deserialization of untrusted data CVE-2024-24590High8.8no fix yet | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML path traversal vulnerability CVE-2024-24591High8.8no fix yet | High8.8 | No fix yet |
| Oct 52025 | clearml is vulnerable to Path Traversal through its `safe_extract` function CVE-2025-8917Medium5.8fixed in 2.0.2 | Medium5.8 | 2.0.2 |