CVE-2024-6851
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.
Vendor
Product
CWE
Yayın Tarihi
2025-03-20 10:15:34
Güncelleme
2025-07-23 20:57:20
Source Identifier
security@huntr.dev
KEV Date Added
-