PT-2025-12220 · Aimhubio · Aim

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8101

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions aimhubio/aim version 3.23.0
Description A stored cross-site scripting (XSS) issue exists in the Text Explorer component due to the use of dangerouslySetInnerHTML without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.
Recommendations For aimhubio/aim version 3.23.0, consider disabling the use of dangerouslySetInnerHTML in the Text Explorer component until a patch is available, or ensure proper sanitization of the content to prevent arbitrary JavaScript execution. Restrict access to the Text Explorer component to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8101

Affected Products

Aim