Medium severity5.4NVD Advisory· Published Jul 29, 2024· Updated Jun 17, 2026
CVE-2024-6578
CVE-2024-6578
Description
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the dangerouslySetInnerHTML function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by injecting malicious scripts into the logs, which will be executed when a user views the logs-tab.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aimPyPI | <= 3.19.3 | — |
Affected products
3- aimhubio/aimhubio/aimv5Range: unspecified
Patches
Vulnerability mechanics
References
3- huntr.com/bounties/5b1ebc67-5346-44aa-b8b8-3c1c09d79680nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-p9f2-jg9w-cx69ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-6578ghsaADVISORY
News mentions
0No linked articles in our index yet.