CVE-2025-5321
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1.
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of the argument Abfrage leads to erweiterte Rechte. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264, CWE-265
- Affected
- aimstack/aim
- Source
- cna@vuldb.com
References
- https://gist.github.com/superboy-zjc/1fc4747a0ac77a1edc8c32e1d4edc54cExploit, Third Party Advisory
- https://vuldb.com/?ctiid.310492Permissions Required, VDB Entry
- https://vuldb.com/?id.310492Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.580253Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.