CVE-2025-0189

HIGH

aimstack aim 3.25.0 - Denial of Service via Large WebSocket Image Upload

Title source: llm
STIX 2.1

Description

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0058
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
aimstack/aim 3.25.0
pypi/aim 0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026