CRITICAL 9.3 NVD
CVE-2026-85663
Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated
Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.
References
- https://github.com/aimhubio/aim
- https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/server.py
- https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/tracking.py
- https://github.com/aimhubio/aim/issues/3412
- https://www.vulncheck.com/advisories/aim-3.29.1-remote-code-execution-via-unauthenticated-
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-04 via NVD.
Risk Timeline
CVE Disclosed2026-09-04 · -1 days ago
Remediation Resources
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.