id: PYSEC-2026-1093 published: "2026-07-07T14:34:41.086169Z" modified: "2026-07-07T17:23:34.954922Z" aliases: - CVE-2024-8863 - GHSA-pmhg-f7wc-c97m summary: Aim Stored XSS through TEXT EXPLORER details: A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. affected: - package: name: aim ecosystem: PyPI purl: pkg:pypi/aim ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 3.24.0 versions: - 2.0.19 - 2.0.20 - 2.0.21 - 2.0.22 - 2.0.23 - 2.0.24 - 2.0.25 - 2.0.26 - 2.0.27 - 2.1.0 - 2.1.1 - 2.1.2 - 2.1.3 - 2.1.4 - 2.1.5 - 2.1.6 - 2.2.0 - 2.2.1 - 2.3.0 - 2.4.0 - 2.5.0 - 2.6.0 - 2.7.0 - 2.7.1 - 2.7.2 - 2.7.3 - 2.7.4 - 3.0.0 - 3.0.1 - 3.0.2 - 3.0.3 - 3.0.4 - 3.0.5 - 3.0.6 - 3.0.7 - 3.1.0 - 3.1.1 - 3.10.0 - 3.10.0.dev9 - 3.10.1 - 3.10.2 - 3.10.3 - 3.11.0 - 3.11.0.dev4 - 3.11.1 - 3.11.1.dev1 - 3.11.2 - 3.12.0 - 3.12.0.dev2 - 3.12.1 - 3.12.2 - 3.13.0 - 3.13.1 - 3.13.2 - 3.13.3 - 3.13.4 - 3.14.0 - 3.14.1 - 3.14.2 - 3.14.3 - 3.14.4 - 3.15.0 - 3.15.1 - 3.15.2 - 3.16.0 - 3.16.1 - 3.16.2 - 3.17.0 - 3.17.1 - 3.17.2 - 3.17.3 - 3.17.4 - 3.17.5 - 3.17.5rc1 - 3.17.5rc2 - 3.17.5rc3 - 3.17.5rc4 - 3.18.0 - 3.18.0.dev2 - 3.18.0.dev3 - 3.18.0.dev4 - 3.18.0.dev5 - 3.18.1 - 3.19.0 - 3.19.1 - 3.19.2 - 3.19.3 - 3.2.0 - 3.2.1 - 3.2.2 - 3.20.1 - 3.21.0 - 3.22.0 - 3.23.0 - 3.24.0 - 3.3.0 - 3.3.1 - 3.3.2 - 3.3.3 - 3.3.4 - 3.3.5 - 3.4.0 - 3.4.1 - 3.5.0 - 3.5.1 - 3.5.2 - 3.5.3 - 3.5.4 - 3.6.0 - 3.6.1 - 3.6.2 - 3.6.3 - 3.7.0 - 3.7.1 - 3.7.2 - 3.7.3 - 3.7.4 - 3.7.5 - 3.8.0 - 3.8.1 - 3.9.0a1 - 3.9.0a14 - 3.9.2 - 3.9.3 - 3.9.4 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-8863 - type: PACKAGE url: https://github.com/aimhubio/aim - type: WEB url: https://rumbling-slice-eb0.notion.site/Stored-XSS-through-TEXT-EXPLORER-in-aimhubio-aim-d0f07b7194724950a673498546d80d43?pvs=4 - type: WEB url: https://vuldb.com/?ctiid.277500 - type: WEB url: https://vuldb.com/?id.277500 - type: WEB url: https://vuldb.com/?submit.403203 - type: PACKAGE url: https://pypi.org/project/aim - type: ADVISORY url: https://github.com/advisories/GHSA-pmhg-f7wc-c97m severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X