Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6888 | A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is concatenated without normalization as part of a path used to specify file deletion. This vulnerability is exposed through the `Repo._close_run()` method, which is accessible via the tracking server instruction API. As a result, an attacker can exploit this to delete any arbitrary file on the machine running the tracking server. |
Github GHSA |
GHSA-4qcx-jx49-6qrh | Aim path traversal in LockManager.release_locks |
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-29 |
Tue, 01 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aimstack
Aimstack aim |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:aimstack:aim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aimstack
Aimstack aim |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is concatenated without normalization as part of a path used to specify file deletion. This vulnerability is exposed through the `Repo._close_run()` method, which is accessible via the tracking server instruction API. As a result, an attacker can exploit this to delete any arbitrary file on the machine running the tracking server. | |
| Title | Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim | |
| Weaknesses | CWE-29 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-10-15T12:50:42.461Z
Reserved: 2024-09-12T21:42:09.583Z
Link: CVE-2024-8769
Updated: 2025-03-20T13:05:09.752Z
Status : Modified
Published: 2025-03-20T10:15:44.220
Modified: 2025-10-15T13:15:55.830
Link: CVE-2024-8769
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA