Skip to content

ClearML security advisories

4 advisories · none critical or high in 12 months · latest Oct 5, 2025

4 advisories

DateAdvisory
Oct 52025clearml is vulnerable to Path Traversal through its `safe_extract` function
CVE-2025-8917Medium5.8fixed in 2.0.2
Feb 62024Allegro AI ClearML path traversal vulnerability
CVE-2024-24591High8.8no fix yet
Feb 62024Allegro AI ClearML vulnerable to deserialization of untrusted data
CVE-2024-24590High8.8no fix yet
Feb 62024Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
CVE-2024-24595Medium6.0no fix yet
About ClearML

Experiment tracking, orchestration and serving.

Packages watched: clearml (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.