Critical severity9.8NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026
CVE-2024-2195
CVE-2024-2195
Description
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the /api/runs/search/run/ endpoint, affecting versions >= 3.0.0. The vulnerability resides in the run_search_api function of the aim/web/api/runs/views.py file, where improper restriction of user access to the RunView object allows for the execution of arbitrary code via the query parameter. This issue enables attackers to execute arbitrary commands on the server, potentially leading to full system compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aimPyPI | >= 3.0.0, <= 3.25.0 | — |
Affected products
3- aimhubio/aimhubio/aimv5Range: unspecified
Patches
Vulnerability mechanics
References
3- huntr.com/bounties/22f2355e-b875-4c01-b454-327e5951c018nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mxvw-cj37-8g2hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-2195ghsaADVISORY
News mentions
0No linked articles in our index yet.