CVE-2025-0189
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
Updated: Mar 28, 2025
CWE ID 400
Summary
CVE-2025-0189 is a denial-of-service vulnerability affecting version 3.25.0 of aimhubio/aim. The issue arises from the tracking server's inability to restrict the size of websocket messages. An attacker can exploit this weakness by sending oversized images, causing the server to become unresponsive while processing the large files. Consequently, the server becomes unavailable to handle other requests, leading to a denial-of-service condition.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aim