CVE-2024-8101

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2024-8101 is a stored cross-site scripting (XSS) vulnerability affecting the Text Explorer component of aimhubio/aim version 3.23.0. The issue stems from the use of `dangerouslySetInnerHTML` without proper sanitization, making it susceptible to malicious JavaScript injection. During the training process, an attacker can introduce malicious HTML content, which is then rendered unsanitized in the Text Explorer, potentially leading to arbitrary code execution and data theft. This vulnerability poses a significant security risk and requires immediate remediation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share