Skip to content
ClearMLGHSA-gvqv-h7hh-6fcc

Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance

Medium6.0CVE-2024-24595 · Published Feb 6, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
clearml
PyPI
<= 1.14.2No fix yet
Details and references

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-312, CWE-522
Also known as
CVE-2024-24595, PYSEC-2026-1257

More ClearML advisories

All ClearML
DateAdvisory
Feb 62024Allegro AI ClearML vulnerable to deserialization of untrusted data
CVE-2024-24590High8.8no fix yet
Feb 62024Allegro AI ClearML path traversal vulnerability
CVE-2024-24591High8.8no fix yet
Oct 52025clearml is vulnerable to Path Traversal through its `safe_extract` function
CVE-2025-8917Medium5.8fixed in 2.0.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.