CVE-2025-51464
22.07.2025, 18:15
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitted to the /api/reports endpoint, which is interpreted and executed by Pyodide when the report is viewed. No sanitisation or sandbox restrictions prevent JavaScript execution via pyodide.code.run_js().
| Vendor | Product | Version |
|---|---|---|
| aimstack | aim | 3.28.0 |
𝑥
= Vulnerable software versions