Aimstack
Aimstack AIM: vulnerabilidades y CVE
Aimstack AIM tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-51464 | Alta (8.8) | 0.61% | — | 22 jul 2025 | Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and… |
| CVE-2025-51463 | Alta (7) | 0.46% | — | 22 jul 2025 | Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted… |
| CVE-2025-5321 | Media (5.3) | 0.60% | — | 29 may 2025 | A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler.… |
| CVE-2025-0190 | Alta (7.5) | 0.63% | — | 20 mar 2025 | In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes… |
| CVE-2025-0189 | Alta (7.5) | 0.63% | — | 20 mar 2025 | In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the… |
| CVE-2024-8769 | Crítica (9.1) | 0.91% | — | 20 mar 2025 | A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is… |
| CVE-2024-8238 | Alta (8.1) | 0.77% | — | 20 mar 2025 | In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an… |
| CVE-2024-8101 | Media (6.1) | 0.44% | — | 20 mar 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization,… |
| CVE-2024-8061 | Alta (7.5) | 0.47% | — | 20 mar 2025 | In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the… |
| CVE-2024-7760 | Crítica (9.6) | 0.52% | — | 20 mar 2025 | aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all… |
| CVE-2024-6851 | Alta (7.5) | 1.0% | — | 20 mar 2025 | In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are… |
| CVE-2024-6829 | Crítica (9.1) | 0.87% | — | 20 mar 2025 | A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The… |
| CVE-2024-6483 | Media (5.3) | 0.87% | — | 20 mar 2025 | A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling… |
| CVE-2024-12778 | Alta (7.5) | 0.78% | — | 20 mar 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web… |
| CVE-2024-12777 | Media (5.9) | 0.47% | — | 20 mar 2025 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect… |
| CVE-2024-10110 | Alta (7.5) | 0.63% | — | 20 mar 2025 | In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial… |
| CVE-2024-8863 | Media (5.3) | 0.50% | — | 14 sept 2024 | A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of… |
| CVE-2024-6578 | Media (5.4) | 0.29% | — | 29 jul 2024 | A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for… |
| CVE-2024-6396 | Crítica (9.8) | 53% | — | 12 jul 2024 | A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper… |
| CVE-2024-6227 | Alta (7.5) | 0.58% | — | 8 jul 2024 | A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself,… |
| CVE-2024-2196 | Alta (8.8) | 0.59% | — | 10 abr 2024 | aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. The… |
| CVE-2024-2195 | Crítica (9.8) | 1.8% | — | 10 abr 2024 | A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the… |
| CVE-2021-43775 | Alta (8.6) | 1.9% | — | 23 nov 2021 | Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.