cvedb.io
CVE-2021-43775
HIGH · CVSS 8.6
EPSS exploitation probability: 0%
Published 2021-11-23T21:15:20.347 · Last modified 2026-06-17T04:11:23.560

Summary

Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0.

Affected products

aimstack — aim

Does this affect you?

Add your gear to cvedb and we'll alert you only when aimstack ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.