A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.
References
Configurations
No configuration.
History
06 Oct 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/588fcdd1-fea4-4cc2-a9f8-851701dcb576 - |
05 Oct 2025, 11:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-05 11:16
Updated : 2025-10-06 15:16
NVD link : CVE-2025-8917
Mitre link : CVE-2025-8917
CVE.ORG link : CVE-2025-8917
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')