CRITICAL9.8
PYSEC-2026-260
Aim Web API vulnerable to Remote Code Execution
Details
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py` file, where improper restriction of user access to the `RunView` object allows for the execution of arbitrary code via the `query` parameter. This issue enables attackers to execute arbitrary commands on the server, potentially leading to full system compromise.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/aim
Introduced in:
3.0.0No fixed version published yet for aim (pip). Pin to a known-safe version or switch to an alternative.