Medium severity5.9NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-12777
CVE-2024-12777
Description
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aimPyPI | <= 3.25.0 | — |
Affected products
3- aimhubio/aimhubio/aimv5Range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/cdf8db79-c290-4fe5-9383-4c518bfba4a8nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-v5pj-jrpv-h6g2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-12777ghsaADVISORY
- github.com/aimhubio/aim/blob/d4ad66ac87606b1f377d3e685e861abb2eef6c45/aim/ext/sshfs/utils.pyghsaWEB
News mentions
0No linked articles in our index yet.