ClearML security advisories
4 advisories · none critical or high in 12 months · latest Oct 5, 2025
4 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 52025 | clearml is vulnerable to Path Traversal through its `safe_extract` function CVE-2025-8917Medium5.8fixed in 2.0.2 | Medium5.8 | 2.0.2 |
| Feb 62024 | Allegro AI ClearML path traversal vulnerability CVE-2024-24591High8.8no fix yet | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML vulnerable to deserialization of untrusted data CVE-2024-24590High8.8no fix yet | High8.8 | No fix yet |
| Feb 62024 | Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance CVE-2024-24595Medium6.0no fix yet | Medium6.0 | No fix yet |
About ClearML
Experiment tracking, orchestration and serving.
Packages watched: clearml (PyPI).