← Back to browse · API

CVE-2024-24594

Severity
CRITICAL
CVSS
9.9
EPSS
0.00594
Risk score
39.81
CISA KEV
No
PoC
No
Published
2024-02-06
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-21996, GHSA-F7F8-8QV6-P289
Products
ClearML:ClearML, ClearML:ClearML 0 ≤*
Sources
euvd EUVD-2024-21996

Description

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.

References