Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6963 | In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion. |
Github GHSA |
GHSA-mrvr-7493-pfq3 | Aim Path Traversal vulnerability |
Wed, 23 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimstack
Aimstack aim |
|
| CPEs | cpe:2.3:a:aimstack:aim:3.22.0:*:*:*:*:python:*:* | |
| Vendors & Products |
Aimstack
Aimstack aim |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion. | |
| Title | Arbitrary File Deletion in aimhubio/aim | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:32:59.392Z
Reserved: 2024-07-17T19:49:43.589Z
Link: CVE-2024-6851
Updated: 2025-03-20T17:52:41.937Z
Status : Analyzed
Published: 2025-03-20T10:15:34.247
Modified: 2025-07-23T20:57:20.730
Link: CVE-2024-6851
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:06:46Z
EUVD
Github GHSA