MEDIUM6.0
PYSEC-2026-1257
Allegro AI ClearML Stores Credentials in Plaintext in MongoDB Instance
Details
Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/clearml
Introduced in:
0No fixed version published yet for clearml (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-24595[ADVISORY]
- https://github.com/allegroai/clearml[PACKAGE]
- https://hiddenlayer.com/research/not-so-clear-how-mlops-solutions-can-muddy-the-waters-of-your-supply-chain[WEB]
- https://pypi.org/project/clearml[PACKAGE]
- https://github.com/advisories/GHSA-gvqv-h7hh-6fcc[ADVISORY]