CVE-2025-8917
MEDIUMclearml < 2.0.2 - Path Traversal and Arbitrary File Write via Symbolic and Hard Link Handling
Title source: llmDescription
A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/588fcdd1-fea4-4cc2-a9f8-851701dcb576
Scores
CVSS v3
5.8
EPSS
0.0003
EPSS Percentile
8.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (2)
allegroai/allegroai/clearml
unspecified - 2.0.2
pypi/clearml
0 - 2.0.2PyPI
Published
Oct 05, 2025
Tracked Since
Feb 18, 2026