VDB
Sign up
—

PYSEC-2026-1087

Aim vulnerable to Cross-site Scripting

Details

Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is viewed. No sanitisation or sandbox restrictions prevent JavaScript execution via pyodide.code.run_js().

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aim
Introduced in: 0

No fixed version published yet for aim (pip). Pin to a known-safe version or switch to an alternative.

References