Skip to content
ZenMLGHSA-j3vq-pmp5-r5xj

Missing ratelimit on passwrod resets in zenml

Medium5.4CVE-2024-4311 · Published Nov 14, 2024 · updated Jul 7, 2026

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the 'Update Password' function, allowing them to take over the user's account. This vulnerability is due to the absence of rate-limiting on the '/api/v1/current-user' endpoint, which does not restrict the number of attempts an attacker can make to guess the current password. Successful exploitation results in the attacker being able to change the password and take control of the account.

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
< 0.57.0rc20.57.0rc2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770
Also known as
CVE-2024-4311, PYSEC-2026-2070

More ZenML advisories

All ZenML
Advisory
ZenML unauthenticated DoS via Multipart Boundry
High7.5Mar 20, 2025
Reflected Cross-Site Scripting (XSS) in zenml
Medium6.1Jun 30, 2024
Improper line feed handling in zenml
Medium4.3Jun 24, 2024
zenml-io/zenml does not expire the session after password reset
Low3.9Jun 8, 2024
Improper authorization in zenml
Medium6.5Jun 6, 2024
Race condition in zenml
Low3.1Jun 6, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.