PT-2025-12220 · Aimhubio · Aim
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-8101
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
aimhubio/aim version 3.23.0
Description
A stored cross-site scripting (XSS) issue exists in the Text Explorer component due to the use of
dangerouslySetInnerHTML without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.Recommendations
For aimhubio/aim version 3.23.0, consider disabling the use of
dangerouslySetInnerHTML in the Text Explorer component until a patch is available, or ensure proper sanitization of the content to prevent arbitrary JavaScript execution. Restrict access to the Text Explorer component to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aim