CVE-2024-24591
ClearML Server vulnerability analysis and mitigation

Overview

A path traversal vulnerability was discovered in Allegro AI's ClearML platform, specifically affecting versions 1.4.0 to 1.14.1 of the client SDK. The vulnerability was identified and disclosed by HiddenLayer's SAI team, with the CVE being assigned on January 25, 2024 (CVE Mitre, HiddenLayer Research).

Technical details

The vulnerability exists within the Datasets class inside the downloadexternal_files method of the ClearML client SDK. When a user interacts with a dataset, particularly when using the Dataset.squash method, the vulnerability can be triggered. The flaw allows an attacker to specify arbitrary file paths through external links, including the ability to use the file:// protocol, which can potentially expose sensitive local files (HiddenLayer Research).

Impact

The vulnerability enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user's system when interacted with. This could potentially lead to sensitive data exposure if local files are moved to externally accessible directories (HiddenLayer Research).

Mitigation and workarounds

Following responsible disclosure practices, the vulnerability was reported to ClearML before public disclosure, and the team worked to resolve the issues within a 90-day window. Users should upgrade to versions newer than 1.14.1 to mitigate this vulnerability (HiddenLayer Research).

Additional resources


SourceThis report was generated using AI

Related ClearML Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-24591HIGH8.8
  • ClearML ServerClearML Server
  • clearml
NoNoFeb 06, 2024
CVE-2024-24590HIGH8.8
  • ClearML ServerClearML Server
  • clearml
NoNoFeb 06, 2024
CVE-2024-24595HIGH7.1
  • ClearML ServerClearML Server
  • clearml
NoNoFeb 05, 2024
CVE-2025-8917MEDIUM5.8
  • ClearML ServerClearML Server
  • clearml
NoYesOct 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management