« Volver al listado

Aimstack

Aimstack AIM: vulnerabilidades y CVE

Aimstack AIM tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses0
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-51464Alta (8.8)0.61%—22 jul 2025
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and…
CVE-2025-51463Alta (7)0.46%—22 jul 2025
Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted…
CVE-2025-5321Media (5.3)0.60%—29 may 2025
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler.…
CVE-2025-0190Alta (7.5)0.63%—20 mar 2025
In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes…
CVE-2025-0189Alta (7.5)0.63%—20 mar 2025
In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the…
CVE-2024-8769Crítica (9.1)0.91%—20 mar 2025
A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is…
CVE-2024-8238Alta (8.1)0.77%—20 mar 2025
In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an…
CVE-2024-8101Media (6.1)0.44%—20 mar 2025
A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization,…
CVE-2024-8061Alta (7.5)0.47%—20 mar 2025
In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the…
CVE-2024-7760Crítica (9.6)0.52%—20 mar 2025
aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all…
CVE-2024-6851Alta (7.5)1.0%—20 mar 2025
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are…
CVE-2024-6829Crítica (9.1)0.87%—20 mar 2025
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The…
CVE-2024-6483Media (5.3)0.87%—20 mar 2025
A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling…
CVE-2024-12778Alta (7.5)0.78%—20 mar 2025
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web…
CVE-2024-12777Media (5.9)0.47%—20 mar 2025
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect…
CVE-2024-10110Alta (7.5)0.63%—20 mar 2025
In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial…
CVE-2024-8863Media (5.3)0.50%—14 sept 2024
A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of…
CVE-2024-6578Media (5.4)0.29%—29 jul 2024
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for…
CVE-2024-6396Crítica (9.8)53%—12 jul 2024
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper…
CVE-2024-6227Alta (7.5)0.58%—8 jul 2024
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself,…
CVE-2024-2196Alta (8.8)0.59%—10 abr 2024
aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stealing data like log records and notes without the user's consent. The…
CVE-2024-2195Crítica (9.8)1.8%—10 abr 2024
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the…
CVE-2021-43775Alta (8.6)1.9%—23 nov 2021
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application10
  2. T1499.004 Application or System Exploitation4
  3. T1565.001 Stored Data Manipulation2
  4. T1059.007 JavaScript1
  5. T1185 Browser Session Hijacking1
  6. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.