Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zenml

First CVE: Feb 27, 2024Active for: 2 yearsTotal CVEs: 14
47.5
VTI Score
High

ZenML is a modestly represented MLOps and machine-learning pipeline orchestration platform whose vulnerability footprint concentrates in a single, widely deployed product serving data science and model-deployment workflows. Its recurring weaknesses span web-tier input handling such as cross-site scripting, resource-allocation and throttling gaps, race conditions in concurrent execution, and improper access control—a mix characteristic of Python-based orchestration platforms that interface between data scientists, infrastructure, and deployed models. Current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zenml over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 27, 2024
2 years ago
Most Recent CVE
Oct 5, 2025
292 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-25723HIGH
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoin
Feb 27, 20248.870NOYES
CVE-2024-2083CRITICAL
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulatin
Apr 16, 20249.944NONO
CVE-2025-8406HIGH
ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_directory` to validate files during `da
Oct 5, 20257.824NONO
CVE-2024-4680HIGH
A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expiration. Specifically, the session
Jun 8, 20248.824NONO
CVE-2024-28424HIGH
zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attacke
Mar 14, 20248.824NONO
CVE-2024-9340HIGH
A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart req
Mar 20, 20257.520NONO
CVE-2024-5062MEDIUM
A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web pa
Jun 30, 20246.118NONO
CVE-2024-2383MEDIUM
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Po
Jun 6, 20246.118NONO
CVE-2024-2035MEDIUM
An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authentica
Jun 6, 20246.518NONO
CVE-2024-4311MEDIUM
zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current passwor
Nov 14, 20245.417NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
43%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (14.3%)
Network12 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (78.6%)
High3 (21.4%)
Unknown0 (0.0%)
User Interaction
None5 (35.7%)
Unknown0 (0.0%)
Required9 (64.3%)
Privileges Required
Low4 (28.6%)
High3 (21.4%)
None7 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zenml.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zenml — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zenml's Products

View all 2 CNAs →

Top CWEs