Skip to content

ZenML security advisories

14 advisories across ZenML

Company profile
DateAdvisory
Oct 52025ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
CVE-2025-8406Medium6.3fixed in 0.84.2
Mar 202025ZenML unauthenticated DoS via Multipart Boundry
CVE-2024-9340High7.5fixed in 0.68.0
Nov 142024Missing ratelimit on passwrod resets in zenml
CVE-2024-4311Medium5.4fixed in 0.57.0rc2
Jun 302024Reflected Cross-Site Scripting (XSS) in zenml
CVE-2024-5062Medium6.1fixed in 0.58.0
Jun 242024Improper line feed handling in zenml
CVE-2024-4460Medium4.3fixed in 0.57.1
Jun 82024zenml-io/zenml does not expire the session after password reset
CVE-2024-4680Low3.9no fix yet
Jun 62024Improper authorization in zenml
CVE-2024-2035Medium6.5fixed in 0.56.2
Jun 62024Race condition in zenml
CVE-2024-2032Low3.1fixed in 0.55.5
Jun 62024Improper authentication in zenml
CVE-2024-2213Low3.3fixed in 0.56.3
Jun 62024Clickjacking in zenml
CVE-2024-2383Medium4.3fixed in 0.56.3
Jun 62024Cross site scripting in zenml
CVE-2024-2171Low3.4fixed in 0.56.2
Apr 162024Directory traversal in zenml
CVE-2024-2083Critical9.9fixed in 0.55.5
Apr 162024zenml Session Fixation vulnerability
CVE-2024-2260Medium4.2fixed in 0.56.2
Feb 272024ZenML Server Remote Privilege Escalation Vulnerability
CVE-2024-25723High6.5fixed in 0.42.2, 0.43.1, 0.44.4, 0.46.7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.