Database/AI/ML frameworks & serving

ClearML web server: XSS
CVSS 9.9CVE-2024-24594AI/ML frameworks & servingcurated
Impact
XSS → code execution in the operator's session
Who can reach it
Attacker-controlled experiment metadata rendered in the UI
What to do
Upgrade; tenant-supplied experiment names become operator-plane payloads
References
Related entries
- Red Hat OpenShift AI (notebook plane): A low-privileged data-scientist account can escalate to full cluster compromiseCVE-2025-10725 · Red Hat OpenShift AI (notebook plane)Critical
- BentoML (file upload): SSRF in the file-upload pathCVE-2025-54381 · BentoML (file upload)Critical
- OpenShift AI MaaS API: any in-cluster pod forges identity headers to impersonate tenantsCVE-2026-14450 · Red Hat OpenShift AI MaaS API (Kuadrant AuthPolicy gateway)Critical
- NVIDIA OpenShell: incomplete input denylist in the sandbox provisioning API allows code executionCVE-2026-65083 · NVIDIA OpenShell (sandbox provisioning API)Critical
- NVIDIA OpenShell: sandbox escape lets confined code run outside the sandboxCVE-2026-65093 · NVIDIA OpenShell (agent sandbox confinement)Critical
- MCPHub: any authenticated user can register an MCP server and run arbitrary commands as the service userCVE-2026-79748 · MCPHub (POST /api/servers, PUT /api/servers/:name)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.