Skip to main content
CRITICAL

CVE-2024-6396

CVSS v3

9.8

CRITICAL

EPSS Score

53.1 %

exploit probability, as of 2026-10-04

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.

Technical details

Published
2024-07-12

Frequently asked questions

What is CVE-2024-6396?

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.

Is CVE-2024-6396 actively exploited?

Active exploitation of CVE-2024-6396 has not been confirmed. Its EPSS score was 53.1% on 2026-10-04, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-6396?

CVE-2024-6396 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2024-6396 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key