CVE-2026-85663 PUBLISHED

Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch

Assigner: VulnCheck
Reserved: 04.09.2026 Published: 04.09.2026 Updated: 04.09.2026

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor aimhubio
Product aim
Versions Default: unaffected
  • affected from 0 to 3.29.1 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Missing Authentication for Critical Function CWE