CVE-2024-6829

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 73

Summary

CVE-2024-6829 is a newly disclosed vulnerability affecting the aimhubio/aim package version 3.19.3. This issue permits an attacker to manipulate the `tarfile.extractall()` function, allowing the extraction of malicious tarfiles to arbitrary locations on the host server. By controlling `repo.path` and `run_hash`, an adversary can bypass directory existence checks and overwrite critical files on the remote tracking server. This vulnerability could potentially be exploited to write arbitrary data and execute further attacks, such as crafting a new SSH key on the target system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share