Zenml

Zenml

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 07.08.2026 16:27:41
  • Zuletzt bearbeitet 08.08.2026 04:17:50

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can repla...

  • EPSS 0.18%
  • Veröffentlicht 24.07.2026 03:27:39
  • Zuletzt bearbeitet 24.07.2026 13:17:23

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `re...

  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 14:11:19
  • Zuletzt bearbeitet 23.07.2026 18:24:39

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenants. This inc...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 05.10.2025 09:00:36
  • Zuletzt bearbeitet 30.10.2025 14:08:25

ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_directory` to validate files during `data.tar.gz` extraction, which fails to effectively detect symbolic and ...

Exploit
  • EPSS 0.94%
  • Veröffentlicht 20.03.2025 10:08:50
  • Zuletzt bearbeitet 15.07.2025 11:15:24

A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart bound...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 14.11.2024 18:15:19
  • Zuletzt bearbeitet 07.05.2025 13:48:33

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the 'Update Password' function, allowing them to take over the us...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 30.06.2024 16:15:03
  • Zuletzt bearbeitet 21.11.2024 09:46:53

A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, specifically within the survey redirect parameter. This...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 08.06.2024 20:15:52
  • Zuletzt bearbeitet 21.11.2024 09:43:22

A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expiration. Specifically, the session does not expire after a password change, enabling an attacker to maint...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 06.06.2024 19:15:54
  • Zuletzt bearbeitet 21.11.2024 09:09:38

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 06.06.2024 19:15:53
  • Zuletzt bearbeitet 15.10.2025 13:15:42

An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. ...