We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.
Reserved 2024-07-17 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
huntr.com/bounties/839703fb-23b7-4dc4-ae81-44cd4740d3f3
Support options