PT-2025-23176 · Aimhubio · Aimhubio Aim
Gavin Zhong
+2
·
Published
2025-05-29
·
Updated
2025-06-01
·
CVE-2025-5321
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
aimhubio aim versions up to 3.29.1
Description
A critical vulnerability was found in the aimhubio aim software. This issue affects the
RestrictedPythonQuery function of the /aim/storage/query.py file in the run view Object Handler component. The manipulation of the Query argument leads to a sandbox issue, which can be initiated remotely. The exploit has been disclosed to the public.Recommendations
For aimhubio aim versions up to 3.29.1, as a temporary workaround, consider disabling the
RestrictedPythonQuery function until a patch is available. Restrict access to the run view Object Handler component to minimize the risk of exploitation. Avoid using the Query argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aimhubio Aim