Skip to main content

Vendor/product archive

aimstack / aim CVEs

Beta · best-effort

23 CVEs tagged to aimstack / aim5 Critical, 12 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-51464

Published Jul 22, 2025

Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/repor…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-51463

Published Jul 22, 2025

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5321

Published May 29, 2025

A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0190

Published Mar 20, 2025

In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0189

Published Mar 20, 2025

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very lar…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8769

Published Mar 20, 2025

A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` par…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8238

Published Mar 20, 2025

In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8101

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetI…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8061

Published Mar 20, 2025

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7760

Published Mar 20, 2025

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowin…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6851

Published Mar 20, 2025

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does no…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6829

Published Mar 20, 2025

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitr…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6483

Published Mar 20, 2025

A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12778

Published Mar 20, 2025

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously fr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12777

Published Mar 20, 2025

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made un…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10110

Published Mar 20, 2025

In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8863

Published Sep 14, 2024

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the compone…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6578

Published Jul 29, 2024

A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generat…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6396

Published Jul 12, 2024

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6227

Published Jul 8, 2024

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the serve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2196

Published Apr 10, 2024

aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2195

Published Apr 10, 2024

A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43775

Published Nov 23, 2021

Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables t…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1