CVE-2025-51463 Information
Jul 23, 2025
cve
Description
Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server’s filesystem via a crafted backup tar file submitted to the run_instruction API which is extracted without path validation during restoration.
Reference
https://github.com/aimhubio/aim https://github.com/aimhubio/aim/pull/3327 https://www.gecko.security/blog/cve-2025-51463
Related CNNVD
CNNVD-202507-2898 (Published: 2025-07-22)
Share on: