{"api_version":"1","generated_at":"2026-07-24T23:41:18+00:00","cve":"CVE-2021-43775","urls":{"html":"https://cve.report/CVE-2021-43775","api":"https://cve.report/api/cve/CVE-2021-43775.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43775","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43775"},"summary":{"title":"CVE-2021-43775","description":"Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-11-23 21:15:00","updated_at":"2023-11-07 03:39:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://github.com/aimhubio/aim/security/advisories/GHSA-8phj-f9w2-cjcc","name":"https://github.com/aimhubio/aim/security/advisories/GHSA-8phj-f9w2-cjcc","refsource":"CONFIRM","tags":[],"title":"Arbitrary file reading vulnerability · Advisory · aimhubio/aim · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/aimhubio/aim/pull/1003","name":"https://github.com/aimhubio/aim/pull/1003","refsource":"MISC","tags":[],"title":"Security issue fix for `/static-files/{path}` endpoint  by mihran113 · Pull Request #1003 · aimhubio/aim · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/aimhubio/aim/issues/999","name":"https://github.com/aimhubio/aim/issues/999","refsource":"MISC","tags":[],"title":"Security vulnerabilty · Issue #999 · aimhubio/aim · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/aimhubio/aim/blob/0b99c6ca08e0ba7e7011453a2f68033e9b1d1bce/aim/web/api/views.py#L9-L16","name":"https://github.com/aimhubio/aim/blob/0b99c6ca08e0ba7e7011453a2f68033e9b1d1bce/aim/web/api/views.py#L9-L16","refsource":"MISC","tags":[],"title":"aim/views.py at 0b99c6ca08e0ba7e7011453a2f68033e9b1d1bce · aimhubio/aim · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/aimhubio/aim/pull/1003/commits/f01266a1a479ef11d7d6c539e7dd89e9d5639738","name":"https://github.com/aimhubio/aim/pull/1003/commits/f01266a1a479ef11d7d6c539e7dd89e9d5639738","refsource":"MISC","tags":[],"title":"Security issue fix for `/static-files/{path}` endpoint  by mihran113 · Pull Request #1003 · aimhubio/aim · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43775","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43775","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43775","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aimstack","cpe5":"aim","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"python","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-43775","qid":"980005","title":"Python (pip) Security Update for aim (GHSA-8phj-f9w2-cjcc)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-43775","STATE":"PUBLIC","TITLE":"Arbitrary file reading vulnerability in Aim"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"aim","version":{"version_data":[{"version_value":"< 3.1.0"}]}}]},"vendor_name":"aimhubio"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}]}]},"references":{"reference_data":[{"name":"https://github.com/aimhubio/aim/security/advisories/GHSA-8phj-f9w2-cjcc","refsource":"CONFIRM","url":"https://github.com/aimhubio/aim/security/advisories/GHSA-8phj-f9w2-cjcc"},{"name":"https://github.com/aimhubio/aim/issues/999","refsource":"MISC","url":"https://github.com/aimhubio/aim/issues/999"},{"name":"https://github.com/aimhubio/aim/pull/1003","refsource":"MISC","url":"https://github.com/aimhubio/aim/pull/1003"},{"name":"https://github.com/aimhubio/aim/pull/1003/commits/f01266a1a479ef11d7d6c539e7dd89e9d5639738","refsource":"MISC","url":"https://github.com/aimhubio/aim/pull/1003/commits/f01266a1a479ef11d7d6c539e7dd89e9d5639738"},{"name":"https://github.com/aimhubio/aim/blob/0b99c6ca08e0ba7e7011453a2f68033e9b1d1bce/aim/web/api/views.py#L9-L16","refsource":"MISC","url":"https://github.com/aimhubio/aim/blob/0b99c6ca08e0ba7e7011453a2f68033e9b1d1bce/aim/web/api/views.py#L9-L16"}]},"source":{"advisory":"GHSA-8phj-f9w2-cjcc","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-11-23 21:15:00","lastModifiedDate":"2023-11-07 03:39:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:aimstack:aim:*:*:*:*:*:python:*:*","versionEndExcluding":"3.1.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43775","Ordinal":"221340","Title":"CVE-2021-43775","CVE":"CVE-2021-43775","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43775","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}