Vulnerability record · CVE-2024-6578 · published 29 July 2024
CVE-2024-6578: Aimstack aim cross-site scripting vulnerability
Aimstack · Aim
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the `dangerouslySetInnerHTML` function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by injecting malicious scripts into the logs, which will be executed when a user views the logs-tab.
Description
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the `dangerouslySetInnerHTML` function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by injecting malicious scripts into the logs, which will be executed when a user views the logs-tab.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://huntr.com/bounties/5b1ebc67-5346-44aa-b8b8-3c1c09d79680 | ExploitIssue TrackingThird Party Advisory |
| https://huntr.com/bounties/5b1ebc67-5346-44aa-b8b8-3c1c09d79680 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2024-6578 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-6578), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.