ClearMLGHSA-m95h-p4gg-wfw3
Allegro AI ClearML path traversal vulnerability
High8.8CVE-2024-24591 · Published Feb 6, 2024 · updated Jul 7, 2026
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| clearml PyPI | >= 0.17.0, <= 1.14.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2024-24591, PYSEC-2026-1258
More ClearML advisories
All ClearML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 52025 | clearml is vulnerable to Path Traversal through its `safe_extract` function | Medium5.8 | 2.0.2 |
| Feb 62024 | Allegro AI ClearML vulnerable to deserialization of untrusted data | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance | Medium6.0 | No fix yet |