CVE-2025-8917: Allegroai Allegroai/clearml

Medium severity, CVSS 5.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.

Affected products

  • Allegroai Allegroai/clearml: before 2.0.2 (fixed in 2.0.2)

Published 2025-10-05. Last modified 2026-10-09.