CVE-2025-51463: Aimstack Aim
High severity, CVSS 7.0. EPSS: 0.5% chance of exploitation in the next 30 days.
Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's filesystem via a crafted backup tar file submitted to the run_instruction API, which is extracted without path validation during restoration.
Affected products
- Aimstack Aim: version 3.28.0 only
Published 2025-07-22. Last modified 2026-06-17.