CVE-2024-6829

Source
https://cve.org/CVERecord?id=CVE-2024-6829
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6829.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6829
Aliases
Published
2025-03-20T10:10:50.251Z
Modified
2026-07-15T01:48:50.058896647Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Arbitrary File Overwrite through tarfile-extraction in aimhubio/aim
Details

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the tarfile.extractall() function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The attacker can control repo.path and run_hash to bypass directory existence checks and extract files to unintended locations, potentially overwriting critical files. This can lead to arbitrary data being written to arbitrary locations on the remote tracking server, which could be used for further attacks such as writing a new SSH key to the target server.

Database specific
{
    "cwe_ids": [
        "CWE-73"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6829.json",
    "cna_assigner": "@huntr_ai"
}
References

Affected packages

Git / github.com/aimhubio/aim

Affected ranges

Type
GIT
Repo
https://github.com/aimhubio/aim
Events
Database specific
{
    "cpe": "cpe:2.3:a:aimstack:aim:3.19.3:*:*:*:*:python:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "3.19.3"
        },
        {
            "last_affected": "3.19.3"
        }
    ]
}

Affected versions

3.*
3.19.3
v3.*
v3.19.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6829.json"