📦 Zenml

by Zenml

🔍 What is Zenml?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-2083

CRITICAL CVSS 9.9 Apr 16, 2024

A directory traversal vulnerability in the zenml-io/zenml repository allows attackers to read arbitrary files on the server by manipulating the 'logs' URI path in API requests. This affects all deploy...

CVE-2025-8406

HIGH CVSS 7.8 Oct 5, 2025

ZenML version 0.83.1 contains a path traversal vulnerability in the PathMaterializer class that allows attackers to write arbitrary files during data.tar.gz extraction. This occurs because the is_path...

CVE-2024-9340

HIGH CVSS 7.5 Mar 20, 2025

This CVE describes a Denial of Service vulnerability in zenml-io/zenml version 0.66.0 where unauthenticated attackers can send specially crafted multipart requests with malformed boundaries to cause i...

CVE-2024-25723

HIGH CVSS 8.8 Feb 27, 2024

This vulnerability in ZenML Server allows remote attackers to escalate privileges by activating user accounts with only a valid username and new password via the /api/v1/users/{user_name_or_id}/activa...

CVE-2024-2035

MEDIUM CVSS 6.5 Jun 6, 2024

This CVE-2024-2035 vulnerability allows any authenticated user in the ZenML platform to modify other users' information, including deactivating their accounts by setting the active status to false. Th...