CVE-2025-8917

⚪ Do wiadomości

Luka w allegroai/clearml umożliwia przejście ścieżki i zapis plików poza zamierzony katalog.

CVSS
5.8
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.

path-traversal rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-10-05 11:16:03 UTC
Ostatnia modyfikacja (NVD)2026-10-09 10:10:00 UTC
Referencje