OpenML operates a modestly represented data-science platform focused on machine learning experimentation and dataset sharing, with its vulnerability footprint centered on the openml.org service. The durable signal across its disclosures centers on access-control weaknesses, including authorization bypass through user-controlled keys, improper access control, and uncontrolled resource consumption, reflecting the authentication and data-isolation demands of a collaborative research platform. Current CVE counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openml over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55796HIGH The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confir | Nov 18, 2025 | 7.5 | 25 | NO | NO |
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated | Sep 29, 2025 | 3.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openml.
Media articles that mention a CVE ID that affects a product developed by Openml — matched by CVE ID, not by vendor name.