CVE-2024-8101

Source
https://cve.org/CVERecord?id=CVE-2024-8101
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8101.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-8101
Published
2025-03-20T10:11:29.974Z
Modified
2026-07-15T01:49:17.552575730Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Stored XSS in aimhubio/aim
Details

A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of dangerouslySetInnerHTML without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8101.json",
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/aimhubio/aim

Affected ranges

Type
GIT
Repo
https://github.com/aimhubio/aim
Events
Database specific
{
    "cpe": "cpe:2.3:a:aimstack:aim:3.23.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.23.0"
        },
        {
            "last_affected": "3.23.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.23.0
v3.*
v3.23.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8101.json"