A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 05 Oct 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten. | |
Title | Path Traversal Leading to Remote Code Execution in allegroai/clearml | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-10-05T10:21:56.317Z
Reserved: 2025-08-13T09:13:24.148Z
Link: CVE-2025-8917

No data.

Status : Received
Published: 2025-10-05T11:16:03.400
Modified: 2025-10-05T11:16:03.400
Link: CVE-2025-8917

No data.

No data.