---
id: CVE-2026-85663
title: >-
  Aim 3.29.1 remote tracking server fails to authenticate requests and
  dispatches arbitrary methods through getattr without allowlist validation
summary: >-
  Aim 3.29.1 remote tracking server fails to authenticate requests and
  dispatches arbitrary methods through getattr without allowlist validation.
  Unauthenticated attackers can register clients, instantiate Repo resources,
  and invoke arbitr…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85663'
references:
  - url: 'https://github.com/aimhubio/aim'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/server.py'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/tracking.py'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/aimhubio/aim/issues/3412'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/aim-3.29.1-remote-code-execution-via-unauthenticated-method-dispatch
    label: disclosure@vulncheck.com
  - url: 'https://github.com/aimhubio/aim/issues/3412'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.005
epssPercentile: 0.41843
ingestedAt: '2026-09-10T16:57:28.705Z'
---

## Overview

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
