CVE-2024-7760

CRITICAL

aim 3.22.0 - Cross-Site Request Forgery via Permissive CORS Settings

Title source: llm
STIX 2.1

Description

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.

References (1)

Core 1
Core References

Scores

CVSS v3 9.6
EPSS 0.0023
EPSS Percentile 45.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
aimstack/aim 3.22.0
pypi/aim 0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026