VDB
Sign up
HIGH8.8

PYSEC-2026-1256

Allegro AI ClearML vulnerable to deserialization of untrusted data

Quick fix

PYSEC-2026-1256 — clearml: upgrade to the fixed version with the command below.

pip install --upgrade 'clearml>=1.14.3rc0'

Details

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/clearml
Introduced in: 0.17.0Fixed in: 1.14.3rc0
Fixpip install --upgrade 'clearml>=1.14.3rc0'

References