{"schema_version":1,"title":"zenml (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in zenml (PyPI): 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-8406, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-zenml","json_url":"https://junglewise.ai/threats/technologies/pypi-zenml.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-zenml","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":5},"latest":[{"cve":"CVE-2025-8406","cvss":3,"epss":0.0037,"slug":"cve-2025-8406-zenml-is-vulnerable-to-path-traversal-through-its-pathmaterializer","title":"PYSEC-2026-2071 - ZenML is vulnerable to Path Traversal through its `PathMaterializer` class","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:06.450033+00:00","url":"https://junglewise.ai/threats/cve-2025-8406-zenml-is-vulnerable-to-path-traversal-through-its-pathmaterializer"},{"cve":"CVE-2024-4311","cvss":3.1,"epss":0.0048,"slug":"cve-2024-4311-missing-ratelimit-on-passwrod-resets-in-zenml","title":"PYSEC-2026-2070 - Missing ratelimit on passwrod resets in zenml","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:44.431797+00:00","url":"https://junglewise.ai/threats/cve-2024-4311-missing-ratelimit-on-passwrod-resets-in-zenml"},{"cve":"CVE-2024-4460","cvss":3,"slug":"cve-2024-4460-improper-line-feed-handling-in-zenml","title":"PYSEC-2026-2068 - Improper line feed handling in zenml","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:35.381629+00:00","url":"https://junglewise.ai/threats/cve-2024-4460-improper-line-feed-handling-in-zenml"},{"cve":"CVE-2024-4680","cvss":3,"epss":0.0041,"slug":"cve-2024-4680-zenml-io-zenml-does-not-expire-the-session-after-password-reset","title":"PYSEC-2026-2069 - zenml-io/zenml does not expire the session after password reset","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:34.551064+00:00","url":"https://junglewise.ai/threats/cve-2024-4680-zenml-io-zenml-does-not-expire-the-session-after-password-reset"},{"cve":"CVE-2024-25723","cvss":3.1,"epss":0.7079,"slug":"cve-2024-25723-zenml-server-remote-privilege-escalation-vulnerability","title":"PYSEC-2026-2072 - ZenML Server Remote Privilege Escalation Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.016802+00:00","url":"https://junglewise.ai/threats/cve-2024-25723-zenml-server-remote-privilege-escalation-vulnerability"},{"cve":"CVE-2024-9340","cvss":3,"epss":0.0095,"slug":"cve-2024-9340-zenml-unauthenticated-dos-via-multipart-boundry","title":"PYSEC-2025-57 - A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consum","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:48+00:00","url":"https://junglewise.ai/threats/cve-2024-9340-zenml-unauthenticated-dos-via-multipart-boundry"},{"cve":"CVE-2024-5062","cvss":3.1,"epss":0.0039,"slug":"cve-2024-5062-zenml-reflected-cross-site-scripting-in-survey-redirect","title":"PYSEC-2024-176 - A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improp","severity":"low","exploited":false,"published_at":"2024-06-30T16:15:03+00:00","url":"https://junglewise.ai/threats/cve-2024-5062-zenml-reflected-cross-site-scripting-in-survey-redirect"},{"cve":"CVE-2024-2383","cvss":3.1,"epss":0.0036,"slug":"cve-2024-2383-clickjacking-in-zenml","title":"PYSEC-2024-194 - A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriat","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:54+00:00","url":"https://junglewise.ai/threats/cve-2024-2383-clickjacking-in-zenml"},{"cve":"CVE-2024-2213","cvss":3.1,"epss":0.0024,"slug":"cve-2024-2213-improper-authentication-in-zenml","title":"PYSEC-2024-193 - An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with a","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:53+00:00","url":"https://junglewise.ai/threats/cve-2024-2213-improper-authentication-in-zenml"},{"cve":"CVE-2024-2171","cvss":3.1,"epss":0.0037,"slug":"cve-2024-2171-cross-site-scripting-in-zenml","title":"PYSEC-2024-170 - A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field.","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:53+00:00","url":"https://junglewise.ai/threats/cve-2024-2171-cross-site-scripting-in-zenml"},{"cve":"CVE-2024-2035","cvss":3.1,"epss":0.0063,"slug":"cve-2024-2035-improper-authorization-in-zenml","title":"PYSEC-2024-169 - An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint.","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:53+00:00","url":"https://junglewise.ai/threats/cve-2024-2035-improper-authorization-in-zenml"},{"cve":"CVE-2024-2032","cvss":3.1,"epss":0.0029,"slug":"cve-2024-2032-race-condition-in-zenml","title":"PYSEC-2024-105 - A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creation of multiple users","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-2032-race-condition-in-zenml"},{"cve":"CVE-2024-2260","cvss":3.1,"epss":0.0044,"slug":"cve-2024-2260-zenml-session-fixation-vulnerability","title":"PYSEC-2024-254 - A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated","severity":"low","exploited":false,"published_at":"2024-04-16T00:15:11+00:00","url":"https://junglewise.ai/threats/cve-2024-2260-zenml-session-fixation-vulnerability"},{"cve":"CVE-2024-2083","cvss":3.1,"epss":0.3749,"slug":"cve-2024-2083-directory-traversal-in-zenml","title":"PYSEC-2024-247 - A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can e","severity":"low","exploited":false,"published_at":"2024-04-16T00:15:11+00:00","url":"https://junglewise.ai/threats/cve-2024-2083-directory-traversal-in-zenml"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"zenml (PyPI)","slug":"pypi-zenml","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Python framework for building, versioning, and managing machine learning model pipelines.","url":"https://junglewise.ai/threats/technologies/pypi-zenml"},"most_severe":[{"cve":"CVE-2024-25723","cvss":3.1,"epss":0.7079,"slug":"cve-2024-25723-zenml-server-remote-privilege-escalation-vulnerability","title":"PYSEC-2026-2072 - ZenML Server Remote Privilege Escalation Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.016802+00:00","url":"https://junglewise.ai/threats/cve-2024-25723-zenml-server-remote-privilege-escalation-vulnerability"},{"cve":"CVE-2024-2083","cvss":3.1,"epss":0.3749,"slug":"cve-2024-2083-directory-traversal-in-zenml","title":"PYSEC-2024-247 - A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can e","severity":"low","exploited":false,"published_at":"2024-04-16T00:15:11+00:00","url":"https://junglewise.ai/threats/cve-2024-2083-directory-traversal-in-zenml"},{"cve":"CVE-2024-2035","cvss":3.1,"epss":0.0063,"slug":"cve-2024-2035-improper-authorization-in-zenml","title":"PYSEC-2024-169 - An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint.","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:53+00:00","url":"https://junglewise.ai/threats/cve-2024-2035-improper-authorization-in-zenml"},{"cve":"CVE-2024-4311","cvss":3.1,"epss":0.0048,"slug":"cve-2024-4311-missing-ratelimit-on-passwrod-resets-in-zenml","title":"PYSEC-2026-2070 - Missing ratelimit on passwrod resets in zenml","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:44.431797+00:00","url":"https://junglewise.ai/threats/cve-2024-4311-missing-ratelimit-on-passwrod-resets-in-zenml"},{"cve":"CVE-2024-2260","cvss":3.1,"epss":0.0044,"slug":"cve-2024-2260-zenml-session-fixation-vulnerability","title":"PYSEC-2024-254 - A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated","severity":"low","exploited":false,"published_at":"2024-04-16T00:15:11+00:00","url":"https://junglewise.ai/threats/cve-2024-2260-zenml-session-fixation-vulnerability"},{"cve":"CVE-2024-5062","cvss":3.1,"epss":0.0039,"slug":"cve-2024-5062-zenml-reflected-cross-site-scripting-in-survey-redirect","title":"PYSEC-2024-176 - A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improp","severity":"low","exploited":false,"published_at":"2024-06-30T16:15:03+00:00","url":"https://junglewise.ai/threats/cve-2024-5062-zenml-reflected-cross-site-scripting-in-survey-redirect"},{"cve":"CVE-2024-2171","cvss":3.1,"epss":0.0037,"slug":"cve-2024-2171-cross-site-scripting-in-zenml","title":"PYSEC-2024-170 - A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field.","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:53+00:00","url":"https://junglewise.ai/threats/cve-2024-2171-cross-site-scripting-in-zenml"},{"cve":"CVE-2024-2383","cvss":3.1,"epss":0.0036,"slug":"cve-2024-2383-clickjacking-in-zenml","title":"PYSEC-2024-194 - A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriat","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:54+00:00","url":"https://junglewise.ai/threats/cve-2024-2383-clickjacking-in-zenml"},{"cve":"CVE-2024-2032","cvss":3.1,"epss":0.0029,"slug":"cve-2024-2032-race-condition-in-zenml","title":"PYSEC-2024-105 - A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creation of multiple users","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-2032-race-condition-in-zenml"},{"cve":"CVE-2024-2213","cvss":3.1,"epss":0.0024,"slug":"cve-2024-2213-improper-authentication-in-zenml","title":"PYSEC-2024-193 - An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with a","severity":"low","exploited":false,"published_at":"2024-06-06T19:15:53+00:00","url":"https://junglewise.ai/threats/cve-2024-2213-improper-authentication-in-zenml"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}