ZenMLGHSA-vf7j-cmrj-pmmm
ZenML Server Remote Privilege Escalation Vulnerability
High6.5CVE-2024-25723 · Published Feb 27, 2024 · updated Jul 7, 2026
ZenML Server in the ZenML package before 0.46.7 for Python allows remote privilege escalation because the `/api/v1/users/{user_name_or_id}/activate` REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zenml PyPI | < 0.42.2 | 0.42.2 |
| >= 0.43.0, < 0.43.1 | 0.43.1 | |
| >= 0.45.0, < 0.46.7 | 0.46.7 | |
| >= 0.44.0, < 0.44.4 | 0.44.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2024-25723, PYSEC-2026-2072
More ZenML advisories
All ZenML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 62024 | Cross site scripting in zenml | Low3.4 | 0.56.2 |
| Jun 62024 | Clickjacking in zenml | Medium4.3 | 0.56.3 |
| Jun 62024 | Improper authentication in zenml | Low3.3 | 0.56.3 |
| Jun 62024 | Race condition in zenml | Low3.1 | 0.55.5 |
| Apr 162024 | zenml Session Fixation vulnerability | Medium4.2 | 0.56.2 |
| Apr 162024 | Directory traversal in zenml | Critical9.9 | 0.55.5 |