© 2025-2026 PySpect
First version without a known vulnerability: 0.68.0
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
Fixed in: 0.84.2
ZenML unauthenticated DoS via Multipart Boundry
Fixed in: 0.68.0, cba152eb9ca3071c8372b0b91c02d9d3351de48d
Missing ratelimit on passwrod resets in zenml
Fixed in: 0.57.0rc2
Reflected Cross-Site Scripting (XSS) in zenml
Fixed in: 0.58.0, 21edd863c0ba53c1110b6f018a07c2d6853cf6d4
Improper line feed handling in zenml
Fixed in: 0.57.1
zenml-io/zenml does not expire the session after password reset
Improper authorization in zenml
Fixed in: 0.56.2, b95f083efffa56831cd41d8ed536aeb0b6038fa3
Race condition in zenml
Fixed in: 0.55.5, afcaf741ef9114c9b32f722f101b97de3d8d147b
Improper authentication in zenml
Fixed in: 0.56.3, 58cb3d987372c91eb605853c35325701733337c2
Clickjacking in zenml
Fixed in: 0.56.3, f863fde1269bc355951f8cfc826c0244d88ad5e9
Cross site scripting in zenml
Fixed in: 0.56.2, 68bcb3ba60cba9729c9713a49c39502d40fb945e
Directory traversal in zenml
Fixed in: 0.55.5
zenml Session Fixation vulnerability
Fixed in: 0.56.2, 68bcb3ba60cba9729c9713a49c39502d40fb945e
ZenML Server Remote Privilege Escalation Vulnerability
Fixed in: 0.42.2, 0.43.1, 0.46.7, 0.44.4