PT-2025-23176 · Aimhubio · Aimhubio Aim

Gavin Zhong

+2

·

Published

2025-05-29

·

Updated

2025-06-01

·

CVE-2025-5321

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aimhubio aim versions up to 3.29.1
Description A critical vulnerability was found in the aimhubio aim software. This issue affects the RestrictedPythonQuery function of the /aim/storage/query.py file in the run view Object Handler component. The manipulation of the Query argument leads to a sandbox issue, which can be initiated remotely. The exploit has been disclosed to the public.
Recommendations For aimhubio aim versions up to 3.29.1, as a temporary workaround, consider disabling the RestrictedPythonQuery function until a patch is available. Restrict access to the run view Object Handler component to minimize the risk of exploitation. Avoid using the Query argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5321
GHSA-GP5H-F9C5-8355

Affected Products

Aimhubio Aim