VYPR

Aim

by Aimstack

Source repositories

CVEs (23)

  • CVE-2024-6483MedMar 20, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used to specify log/metadata…

  • CVE-2024-6578MedJul 29, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the…

  • CVE-2024-8863LowSep 14, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is…

Page 2 of 2