CVE-2024-24590

HIGH

Allegro AI's ClearML <1.14.2 - Code Injection

Title source: llm

Description

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

Exploits (8)

nomisec WORKING POC 9 stars
by diegogarciayala · poc
https://github.com/diegogarciayala/CVE-2024-24590-ClearML-RCE-CMD-POC
nomisec WORKING POC 6 stars
by rippsec · poc
https://github.com/rippsec/CVE-2024-24590-ClearML-RCE-Exploit
nomisec WORKING POC 6 stars
by rippxsec · poc
https://github.com/rippxsec/CVE-2024-24590-ClearML-RCE-Exploit
nomisec WORKING POC 6 stars
by OxyDeV2 · poc
https://github.com/OxyDeV2/ClearML-CVE-2024-24590
nomisec WORKING POC 4 stars
by sviim · poc
https://github.com/sviim/ClearML-CVE-2024-24590-RCE
nomisec WORKING POC 1 stars
by junnythemarksman · poc
https://github.com/junnythemarksman/CVE-2024-24590
nomisec WORKING POC
by j3r1ch0123 · poc
https://github.com/j3r1ch0123/CVE-2024-24590

Scores

CVSS v3 8.0
EPSS 0.8283
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

clear/clearml < 1.14.2
pypi/clearml PyPI

Timeline

Published Feb 06, 2024
Tracked Since Feb 18, 2026