CVE-2024-24591: Clear Clearml
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.
Affected products
- Clear Clearml: from 1.4.0, up to and including 1.14.1
Published 2024-02-06. Last modified 2026-06-17.