CVE-2025-51463 Information

Description

Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server’s filesystem via a crafted backup tar file submitted to the run_instruction API which is extracted without path validation during restoration.

Reference

https://github.com/aimhubio/aim https://github.com/aimhubio/aim/pull/3327 https://www.gecko.security/blog/cve-2025-51463

CNNVD-202507-2898 (Published: 2025-07-22)

Share on: