Cyber Resilience

CVE-2025-5321

Aimstack Aim ≤ 3.29.1

Public PoC
Published
29 May 2025
Modified
17 June 2026
CVSS Score v4 5.3
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0050 40th percentile
Risk Priority 33 floored blend · peak EPSS

Summary

CVE-2025-5321 is a medium-severity an unspecified weakness vulnerability in Aimstack Aim. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 40th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of the argument Abfrage leads to erweiterte Rechte. The…

more

attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-8238Same product: Aimstack Aim
CVE-2024-10110Same product: Aimstack Aim
CVE-2025-0189Same product: Aimstack Aim
CVE-2025-0190Same product: Aimstack Aim
CVE-2024-8101Same product: Aimstack Aim
CVE-2024-12778Same product: Aimstack Aim
CVE-2024-8863Same product: Aimstack Aim
CVE-2024-6483Same product: Aimstack Aim
CVE-2024-7760Same product: Aimstack Aim
CVE-2024-12777Same product: Aimstack Aim

Affected Assets

aimstack
aim
≤ 3.29.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References