CVE-2024-28424

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
14/03/2024
Last modified:
05/05/2025

Description

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zenml:zenml:0.55.4:*:*:*:*:*:*:*