A vulnerability in Allegro AI’s ClearML client SDK (versions 0.17.0 to 1.14.2) allows deserialization of untrusted data. When a user interacts with a maliciously uploaded artifact, arbitrary code execution can occur on the end user's system due to unsafe deserialization routines in the SDK.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2024-24590 affecting ClearML versions 0.17.0 through 1.14.2. It contains three files: a README with vulnerability description and usage guidance, a requirements.txt listing clearml/pwntools/colorama, and a single executable script, exploit.py, which is the main entry point. The exploit abuses unsafe pickle deserialization in ClearML artifacts. The script helps the operator initialize ClearML credentials via clearml-init, then constructs a malicious Python object whose __reduce__ method returns os.system with a shell command. That object is uploaded as a ClearML artifact using Task.init(...) and task.upload_artifact(...). When a victim user or automated pipeline later retrieves and deserializes the artifact, the embedded command executes on the victim machine. Operationally, the payload is a base64-wrapped bash reverse shell using /dev/tcp/<attacker_ip>/<attacker_port>. The script prompts for attacker IP, port, and target ClearML project name, and can optionally launch a local pwncat listener bound to 0.0.0.0 on the chosen port. This makes the exploit more than a bare proof of concept: it is a usable offensive script with a hardcoded but parameterized reverse-shell payload. There are no hardcoded remote ClearML server URLs in the code; the target server is determined indirectly through the operator's ClearML client configuration in ~/clearml.conf. The exploit requires authenticated write access to a ClearML project and depends on a victim subsequently loading the malicious artifact. Overall, the repository's purpose is to weaponize ClearML artifact deserialization into remote code execution on downstream consumers of shared artifacts.
Repository contains a single Python exploit (exploit.py) plus README and requirements.txt. It targets CVE-2024-24590 in ClearML (versions 0.17.0–1.14.2), abusing unsafe pickle deserialization of ClearML artifacts to achieve RCE on the system that deserializes the artifact. Core behavior: the script builds a malicious Python object with a __reduce__ method that returns (os.system, (cmd,)), where cmd is a base64-wrapped bash reverse shell. It then uses the ClearML SDK (Task.init + task.upload_artifact) to upload this object as an artifact (name: 'pickle_artifact') into a user-specified ClearML project (case-sensitive). Exploitation is not immediate on upload; it requires a second party (another user/agent) to deserialize/load the artifact, at which point the command executes. Operator workflow: (1) optionally run 'Initialize ClearML' which backs up ~/clearml.conf to ~/clearml.conf.bak and runs 'clearml-init' to configure server credentials; (2) run exploit, providing LHOST, LPORT, and target project name; (3) optionally start a pwncat listener bound to 0.0.0.0:LPORT. Dependencies listed are colorama, clearml, and pwntools.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-24590, targeting the ClearML MLOps platform. It contains two files: a README.md with usage instructions and context, and exploit.py, the main exploit script. The exploit leverages the ability to upload a malicious pickle artifact to a ClearML task. The pickle object is crafted so that, when deserialized by ClearML, it executes a reverse shell command using netcat, connecting back to an attacker-specified IP and port. The script is configurable via command-line arguments for project/task names, tags, artifact name, and the attacker's IP/port. The attack vector is network-based, requiring the attacker to have access to upload artifacts to a ClearML instance. The exploit demonstrates the risk of unsafe deserialization in ClearML's artifact handling. No hardcoded endpoints are present, but the reverse shell targets attacker-supplied IP/port, and the exploit uses a temporary file (/tmp/f) for the shell FIFO.
This repository contains a Python exploit script (exploit.py) and a README.md. The exploit targets ClearML instances vulnerable to CVE-2024-24590, CVE-2024-24591, and CVE-2024-24592. The script leverages the ClearML SDK to upload a malicious pickle artifact to a specified project and task. When the artifact is deserialized by ClearML, it executes arbitrary OS commands on the target system. In 'default' mode, the exploit establishes a reverse shell to an attacker-controlled IP and port using netcat. In 'cmd' mode, it executes a custom command provided by the attacker. The script allows customization of project and task names and optionally sets a tag on the task. The main entry point is exploit.py, which uses Python's argparse for command-line arguments and requires the ClearML SDK. The exploit demonstrates a real-world remote code execution (RCE) scenario via insecure deserialization in ClearML's artifact handling.
This repository contains an exploit for CVE-2024-24590, a vulnerability in ClearML related to unsafe deserialization of Pickle objects. The exploit is implemented in 'scriptls.py', which crafts a malicious Pickle object that, when deserialized by a vulnerable ClearML server, executes a reverse shell command. The script uses the ClearML Python API to upload this malicious artifact. The attacker must specify their own IP and port to receive the reverse shell. The README provides a brief overview and setup instructions. The exploit demonstrates operational maturity, as it provides a working payload and clear instructions for use. No hardcoded external endpoints are present, but the attacker must configure the script with their own listener details.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.