Back

MEDIUM

Path Traversal Leading to Remote Code Execution in allegroai/clearml

Published Oct 5, 2025

Description

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Oct 5, 2025
Updated Oct 6, 2025
Reserved Aug 13, 2025
CISA Vulnrichment
Updated Oct 6, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-579P-QF78-FQM2