---
id: CVE-2024-8863
aliases:
  - GHSA-pmhg-f7wc-c97m
  - PYSEC-2026-1093
title: Aim Stored XSS through TEXT EXPLORER
summary: Aim Stored XSS through TEXT EXPLORER
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
vendor: aim
product: aim
ecosystem: pip
affected:
  - aim <= 3.24.0
published: '2024-09-16'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:18.431413825Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pmhg-f7wc-c97m'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-8863'
  - url: 'https://github.com/aimhubio/aim'
  - url: >-
      https://rumbling-slice-eb0.notion.site/Stored-XSS-through-TEXT-EXPLORER-in-aimhubio-aim-d0f07b7194724950a673498546d80d43?pvs=4
  - url: 'https://vuldb.com/?ctiid.277500'
  - url: 'https://vuldb.com/?id.277500'
  - url: 'https://vuldb.com/?submit.403203'
tags:
  - osv
  - pip
epss: 0.00503
epssPercentile: 0.4206
ingestedAt: '2026-07-08T18:25:51.793Z'
---

## Overview

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected packages

- `aim <= 3.24.0`

## Remediation

Refer to the advisory for the patched release.
