CVE-2026-85663
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aimhubio | aim | 0 <= 3.29.1 | affected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: total
Additional References
References
- https://github.com/aimhubio/aim/issues/3412
- https://github.com/aimhubio/aim
- https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/tracking.py
- https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/server.py
- https://www.vulncheck.com/advisories/aim-3.29.1-remote-code-execution-via-unauthenticated-method-dispatch
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.