MEDIUM5.9
PYSEC-2026-1095
Aim vulnerable to Synchronous Access of Remote Resource without Timeout
Details
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/aim
Introduced in:
0No fixed version published yet for aim (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-12777[ADVISORY]
- https://github.com/aimhubio/aim[PACKAGE]
- https://github.com/aimhubio/aim/blob/d4ad66ac87606b1f377d3e685e861abb2eef6c45/aim/ext/sshfs/utils.py#L151-L154[WEB]
- https://huntr.com/bounties/cdf8db79-c290-4fe5-9383-4c518bfba4a8[WEB]
- https://pypi.org/project/aim[PACKAGE]
- https://github.com/advisories/GHSA-v5pj-jrpv-h6g2[ADVISORY]