CVE-2024-2195

A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py` file, where improper restriction of user access to the `RunView` object allows for the execution of arbitrary code via the `query` parameter. This issue enables attackers to execute arbitrary commands on the server, potentially leading to full system compromise.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:aimstack:aim:*:*:*:*:*:python:*:*

History

29 Jul 2025, 20:31

Type Values Removed Values Added
CPE cpe:2.3:a:aimstack:aim:*:*:*:*:*:python:*:*
First Time Aimstack aim
Aimstack
References () https://huntr.com/bounties/22f2355e-b875-4c01-b454-327e5951c018 - () https://huntr.com/bounties/22f2355e-b875-4c01-b454-327e5951c018 - Exploit, Third Party Advisory
CWE CWE-94

10 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 17:15

Updated : 2025-07-29 20:31


NVD link : CVE-2024-2195

Mitre link : CVE-2024-2195


JSON object : View

Products Affected

aimstack

  • aim
CWE

No CWE.