Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6999 | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests. |
Github GHSA |
GHSA-v5pj-jrpv-h6g2 | Aim vulnerable to Synchronous Access of Remote Resource without Timeout |
Fri, 18 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimstack
Aimstack aim |
|
| CPEs | cpe:2.3:a:aimstack:aim:3.25.0:*:*:*:*:python:*:* | |
| Vendors & Products |
Aimstack
Aimstack aim |
Thu, 20 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests. | |
| Title | Denial of Service in aimhubio/aim | |
| Weaknesses | CWE-1088 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T13:30:19.041Z
Reserved: 2024-12-18T22:43:21.059Z
Link: CVE-2024-12777
Updated: 2025-03-20T13:30:09.229Z
Status : Analyzed
Published: 2025-03-20T10:15:30.360
Modified: 2025-07-18T20:01:55.330
Link: CVE-2024-12777
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:42:24Z
EUVD
Github GHSA