VDB
Sign up
CRITICAL9.8

PYSEC-2026-260

Aim Web API vulnerable to Remote Code Execution

Details

A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py` file, where improper restriction of user access to the `RunView` object allows for the execution of arbitrary code via the `query` parameter. This issue enables attackers to execute arbitrary commands on the server, potentially leading to full system compromise.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aim
Introduced in: 3.0.0

No fixed version published yet for aim (pip). Pin to a known-safe version or switch to an alternative.

References