clearml
ClearML - Auto-Magical CI/CD to streamline your AI workload. Experiment Management, Data Management, Pipeline, Orchestration, Scheduling & Serving in one MLOps/LLMOps solution
Activity
- Latest release
- 3w ago
- Total releases
- 199
- Cadence
- ~13 days
- Last 12 months
- 18
Reach
- Stars
- 6.8k
Details
- License
- Apache-2.0
- First release
- Dec 22, 2020
| Version | Released | |
|---|---|---|
2.1.12
patch
| ||
2.1.11
patch
| ||
2.1.10
patch
| ||
2.1.9
patch
| ||
2.1.8
patch
| ||
2.1.7
patch
| ||
2.1.6
patch
| ||
2.1.6rc0
pre
| ||
2.1.5
patch
| ||
2.1.4
patch
| ||
2.1.4rc1
pre
| ||
2.1.4rc0
pre
| ||
2.1.3
patch
| ||
2.1.2
patch
| ||
2.1.1
patch
| ||
2.1.0
minor
| ||
2.1.1rc0
pre
| ||
2.0.3rc1
pre
| ||
2.0.3rc0
pre
| ||
2.0.2
patch
| ||
2.0.1
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.0rc1
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
2.0.0rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.18.0
minor
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.17.2rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.17.1
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.17.0
minor
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.17.0rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.5
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.5rc2
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.5rc1
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.5rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.4
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.3
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.3rc2
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.3rc1
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.3rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.2
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.2rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.1
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.0
minor
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.16.0rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.15.1
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.14.5rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.14.4
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.14.4rc1
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.14.4rc0
pre
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.14.3
patch
1 CVE
CVE-2025-8917
PYSEC-2026-1255
GHSA-579p-qf78-fqm2
Jul 07, 2026
clearml is vulnerable to Path Traversal through its `safe_extract` function
5.8
/ 10
Medium
Local
Low
High
Required
Unchanged
High
High
None
A vulnerability in clearml versions before 2.0.2 allows for path traversal due to improper handling of symbolic and hard links in the Affected versions
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.5rc0
0.17.5rc1
0.17.5rc2
0.17.5rc3
0.17.5rc4
0.17.5rc5
+ 167 more Show less
0.17.5rc6
0.17.6rc1
1.0.0
1.0.1
1.0.2
1.0.2rc0
1.0.3
1.0.3rc0
1.0.3rc1
1.0.4
1.0.4rc0
1.0.4rc1
1.0.5
1.0.6rc1
1.0.6rc2
1.1.0
1.1.1
1.1.2
1.1.2rc0
1.1.3
1.1.3rc0
1.1.4
1.1.4rc0
1.1.5
1.1.5rc0
1.1.5rc1
1.1.5rc2
1.1.5rc3
1.1.5rc4
1.1.5rc5
1.1.5rc6
1.1.5rc7
1.1.6
1.1.6rc0
1.10.0
1.10.0rc0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.4rc0
1.10.4rc1
1.11.0
1.11.0rc0
1.11.1
1.11.1rc0
1.11.1rc1
1.11.1rc2
1.11.2rc0
1.12.0
1.12.1
1.12.1rc0
1.12.2
1.12.2rc0
1.13.0
1.13.1
1.13.2
1.13.2rc0
1.13.2rc1
1.13.2rc2
1.13.2rc3
1.13.3rc0
1.13.3rc1
1.14.0
1.14.0rc0
1.14.1
1.14.1rc0
1.14.2
1.14.2rc0
1.14.3
1.14.3rc0
1.14.4
1.14.4rc0
1.14.4rc1
1.14.5rc0
1.15.0
1.15.1
1.16.0
1.16.0rc0
1.16.1
1.16.2
1.16.2rc0
1.16.3
1.16.3rc0
1.16.3rc1
1.16.3rc2
1.16.4
1.16.5
1.16.5rc0
1.16.5rc1
1.16.5rc2
1.17.0
1.17.0rc0
1.17.1
1.17.2rc0
1.18.0
1.2.0
1.2.0rc0
1.2.0rc1
1.2.0rc2
1.2.1
1.2.1rc0
1.3.0
1.3.0rc0
1.3.0rc1
1.3.0rc2
1.3.1
1.3.1rc0
1.3.2
1.3.2rc0
1.3.2rc1
1.3.2rc2
1.3.2rc3
1.3.2rc4
1.3.3rc0
1.3.3rc1
1.3.3rc2
1.4.0
1.4.1
1.4.1rc0
1.4.2rc0
1.4.2rc1
1.5.0
1.6.0
1.6.1
1.6.2
1.6.2rc0
1.6.3
1.6.3rc0
1.6.3rc1
1.6.4
1.6.5rc0
1.6.5rc1
1.6.5rc2
1.7.0
1.7.0rc0
1.7.0rc1
1.7.1
1.7.1rc0
1.7.1rc1
1.7.1rc2
1.7.2
1.7.2rc0
1.7.2rc1
1.7.2rc2
1.7.3rc0
1.7.3rc1
1.8.0
1.8.1
1.8.1rc0
1.8.2
1.8.3
1.8.4rc0
1.8.4rc1
1.8.4rc2
1.9.0
1.9.1
1.9.1rc0
1.9.2
1.9.2rc0
1.9.2rc1
1.9.2rc2
1.9.3
2.0.0
2.0.0rc0
2.0.0rc1
2.0.1
Fixed in
2.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev |