CVE-2024-6483
MEDIUMaimhubio/aim <3.19.3 - Path Traversal
Title source: llmDescription
A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used to specify log/metadata files for deletion. This can be exploited to delete arbitrary files or directories, potentially causing denial of service or data loss.
Scores
CVSS v3
5.3
EPSS
0.0027
EPSS Percentile
50.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-23
Status
published
Affected Products (2)
aimstack/aim
pypi/aim
PyPI
Timeline
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026