CVE-2025-8917

MEDIUM

clearml < 2.0.2 - Path Traversal and Arbitrary File Write via Symbolic and Hard Link Handling

Title source: llm
STIX 2.1

Description

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.

Scores

CVSS v3 5.8
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
allegroai/allegroai/clearml unspecified - 2.0.2
pypi/clearml 0 - 2.0.2PyPI
Published Oct 05, 2025
Tracked Since Feb 18, 2026