High severity7.0NVD Advisory· Published Jul 22, 2025· Updated Jun 17, 2026
CVE-2025-51463
CVE-2025-51463
Description
Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- AIM/AIMdescription
Patches
Vulnerability mechanics
References
2- github.com/aimhubio/aim/pull/3327nvdExploitIssue Tracking
- www.gecko.security/blog/cve-2025-51463nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.