Aim npm Package Authentication Flaw: Critical Vulnerability
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- aim (npm)
- Affected versions
- >= v3.29.1, <= v3.29.1 or >= v3.28.0, <= v3.28.0 or >= v3.27.0, <= v3.27.0 or >= v3.26.1, <= v3.26.1 or >= v3.25.1, <= v3.25.1 or >= v3.25.0, <= v3.25.0 or >= v3.24.0, <= v3.24.0 or >= v3.23.0, <= v3.23.0 or >= v3.22.0, <= v3.22.0 or >= v3.21.0, <= v3.21.0 or >= v3.20.1, <= v3.20.1 or >= v3.19.1, <= v3.19.1 or >= v3.19.0, <= v3.19.0 or >= v3.18.1, <= v3.18.1 or >= v3.17.5, <= v3.17.5 or >= v3.17.4, <= v3.17.4 or >= v3.17.3, <= v3.17.3 or >= v3.17.2, <= v3.17.2 or >= v3.17.1, <= v3.17.1 or >= v3.17.0, <= v3.17.0 or >= v3.5.0, <= v3.5.0 or >= v3.4.0, <= v3.4.0 or >= v3.3.2, <= v3.3.2 or >= v3.3.1, <= v3.3.1 or >= v3.3.0, <= v3.3.0 or >= v3.2.0, <= v3.2.0 or >= v3.1.1, <= v3.1.1 or >= v3.1.0, <= v3.1.0 or >= v3.0.2, <= v3.0.2 or >= v3.0.1, <= v3.0.1 or >= v3.0.0, <= v3.0.0 or >= v3.0.0-beta6, <= v3.0.0-beta6 or >= v3.0.0-beta5, <= v3.0.0-beta5 or >= v2.7.0, <= v2.7.0 or >= v2.6.0, <= v2.6.0 or >= v2.5.0, <= v2.5.0 or >= v2.4.0, <= v2.4.0 or >= v2.3.0, <= v2.3.0 or >= v2.2.0, <= v2.2.0 or >= v2.1.6, <= v2.1.6 or >= pre-launch, <= pre-launch or >= v1.2.7rc1, <= v1.2.7rc1 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.0, <= v1.0.0 or >= v0.2.6, <= v0.2.6 or >= v0.2.5, <= v0.2.5 or >= v0.2.4, <= v0.2.4 or >= v0.2.3, <= v0.2.3 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.1, <= v0.1.1 or >= v0.1.0, <= v0.1.0
- Patched version
- Not yet available
The Aim npm package versions from v0.1.0 to v3.29.1 contain a critical authentication flaw allowing unauthenticated access. Users of these versions are affected.
What happened
The Aim npm package, versions from v0.1.0 to v3.29.1, has been confirmed to have a critical vulnerability. This flaw allows unauthenticated attackers to register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs. The vulnerability was first flagged on September 4, 2026, and confirmed on September 8, 2026. The flaw has a CVSS score of 9.8, indicating a critical severity level.
To assess your exposure, check if your project dependencies include any version of Aim within the affected range. If so, you are vulnerable to this authentication bypass attack.
What to do about it
- Identify and list all instances where Aim is used in your project dependencies.
- Upgrade Aim to a version that includes proper authentication and method validation. No specific patched version is mentioned, so monitor the primary sources for updates.
- Review your project for any additional security measures that can be implemented to mitigate the risk of unauthenticated access.
- Test your application thoroughly after the upgrade to ensure that the vulnerability has been addressed and no new issues have been introduced.
How 0Day would have caught this
aim is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your project uses Aim npm package versions from v0.1.0 to v3.29.1.
What should I do right now?
Immediately identify and upgrade any instances of Aim in your project to a version that includes proper authentication and method validation. Monitor primary sources for updates on a patched version.
Is there a patched version available?
No official patched version has been published yet. Continue to monitor primary sources for updates.
Sources
- [GHSA-p569-5gjg-9cmj] rclone: RC per-server auth-proxy bypass
- [GHSA-x99w-6fgc-pmfw] NLTK: Allowlisted pickle loaders still permit code execution in current source
- [GHSA-3cgp-3cqx-j8w2] Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
- [CVE-2026-13447] CVSS 9.8 CRITICAL
- [CVE-2026-85663] CVSS 9.8 CRITICAL
- Veradigm warns of patient data breach after ransomware gang claims attack