Aimstack

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 23
    Known Exploited: 0
    5
    Critical Level Threats
    12
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-51464

    Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is viewed. No sanitisation or sandbox restrictions prevent JavaScript execution via pyodide.code.run_js().

    Last Modified: Sep 11, 2025
    Published: Jul 22, 2025

    CVE-2025-51463

    Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.

    Last Modified: Sep 11, 2025
    Published: Jul 22, 2025

    CVE-2025-5321

    aimhubio aim run_view Object query.py RestrictedPythonQuery privilege escalation

    Last Modified: Sep 19, 2025
    Published: May 29, 2025

    CVE-2024-8101

    Stored XSS in aimhubio/aim

    Last Modified: Apr 01, 2025
    Published: Mar 20, 2025

    CVE-2024-8769

    Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim

    Last Modified: Oct 15, 2025
    Published: Mar 20, 2025
    Items Per Page