CVE-2025-0190
HIGHaim 3.25.0 - Denial of Service via Excessive Text Object Queries
Title source: llmDescription
In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing and returning these objects. This vulnerability can be exploited repeatedly, leading to a complete denial of service.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/38d151f1-abb4-443a-86b0-6c26f0c6cb70
Scores
CVSS v3
7.5
EPSS
0.0044
EPSS Percentile
63.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1049
Status
published
Products (2)
aimstack/aim
3.25.0
pypi/aim
0PyPI
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026