CVE-2025-51464 describes a critical Cross-site Scripting (XSS) vulnerability in aimhubio Aim version 3.28.0. This flaw allows remote attackers to execute arbitrary JavaScript in a victim's browser by submitting malicious Python code to the /api/reports endpoint, which is then executed by Pyodide without proper sanitization or sandboxing. Rated with a CVSS score of 8.8 (HIGH), this vulnerability has a network attack vector, low attack complexity, and a severe potential impact on confidentiality, integrity, and availability. The lack of input sanitization and the ability to execute JavaScript via pyodide.code.run_js() contribute to its high severity. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of disclosed vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.28.0CPE matchmatch criteria | cpe:2.3:a:aimstack:aim:3.28.0:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.