Home

Description

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.

PUBLISHED Reserved 2025-06-16 | Published 2025-07-22 | Updated 2025-07-22 | Assigner mitre

References

github.com/aimhubio/aim

github.com/aimhubio/aim/pull/3327

www.gecko.security/blog/cve-2025-51463

cve.org (CVE-2025-51463)

nvd.nist.gov (CVE-2025-51463)

Download JSON