Skip to content
ZenMLGHSA-vf7j-cmrj-pmmm

ZenML Server Remote Privilege Escalation Vulnerability

High6.5CVE-2024-25723 · Published Feb 27, 2024 · updated Jul 7, 2026

ZenML Server in the ZenML package before 0.46.7 for Python allows remote privilege escalation because the `/api/v1/users/{user_name_or_id}/activate` REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
< 0.42.20.42.2
>= 0.43.0, < 0.43.10.43.1
>= 0.45.0, < 0.46.70.46.7
>= 0.44.0, < 0.44.40.44.4
Details and references

More ZenML advisories

All ZenML
Advisory
Cross site scripting in zenml
Low3.4Jun 6, 2024
Clickjacking in zenml
Medium4.3Jun 6, 2024
Improper authentication in zenml
Low3.3Jun 6, 2024
Race condition in zenml
Low3.1Jun 6, 2024
zenml Session Fixation vulnerability
Medium4.2Apr 16, 2024
Directory traversal in zenml
Critical9.9Apr 16, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.