A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw can lead to arbitrary file writes outside the intended directory, potentially resulting in remote code execution if critical files are overwritten.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-10-05 11:16
Updated : 2025-10-06 15:16
NVD link : CVE-2025-8917
Mitre link : CVE-2025-8917
CVE.ORG link : CVE-2025-8917
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
