CVE-2024-6483

Severity CVSS v4.0:
Pending analysis
Type:
CWE-23 Relative Path Traversal
Publication date:
20/03/2025
Last modified:
23/07/2025

Description

A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used to specify log/metadata files for deletion. This can be exploited to delete arbitrary files or directories, potentially causing denial of service or data loss.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aimstack:aim:3.19.3:*:*:*:*:python:*:*


References to Advisories, Solutions, and Tools