NPM · SEPTEMBER 2026 · CONFIRMED

Aim npm Package Authentication Flaw: Critical Vulnerability

Severity
CRITICAL
CVSS
9.8
Affected component
aim (npm)
Affected versions
>= v3.29.1, <= v3.29.1 or >= v3.28.0, <= v3.28.0 or >= v3.27.0, <= v3.27.0 or >= v3.26.1, <= v3.26.1 or >= v3.25.1, <= v3.25.1 or >= v3.25.0, <= v3.25.0 or >= v3.24.0, <= v3.24.0 or >= v3.23.0, <= v3.23.0 or >= v3.22.0, <= v3.22.0 or >= v3.21.0, <= v3.21.0 or >= v3.20.1, <= v3.20.1 or >= v3.19.1, <= v3.19.1 or >= v3.19.0, <= v3.19.0 or >= v3.18.1, <= v3.18.1 or >= v3.17.5, <= v3.17.5 or >= v3.17.4, <= v3.17.4 or >= v3.17.3, <= v3.17.3 or >= v3.17.2, <= v3.17.2 or >= v3.17.1, <= v3.17.1 or >= v3.17.0, <= v3.17.0 or >= v3.5.0, <= v3.5.0 or >= v3.4.0, <= v3.4.0 or >= v3.3.2, <= v3.3.2 or >= v3.3.1, <= v3.3.1 or >= v3.3.0, <= v3.3.0 or >= v3.2.0, <= v3.2.0 or >= v3.1.1, <= v3.1.1 or >= v3.1.0, <= v3.1.0 or >= v3.0.2, <= v3.0.2 or >= v3.0.1, <= v3.0.1 or >= v3.0.0, <= v3.0.0 or >= v3.0.0-beta6, <= v3.0.0-beta6 or >= v3.0.0-beta5, <= v3.0.0-beta5 or >= v2.7.0, <= v2.7.0 or >= v2.6.0, <= v2.6.0 or >= v2.5.0, <= v2.5.0 or >= v2.4.0, <= v2.4.0 or >= v2.3.0, <= v2.3.0 or >= v2.2.0, <= v2.2.0 or >= v2.1.6, <= v2.1.6 or >= pre-launch, <= pre-launch or >= v1.2.7rc1, <= v1.2.7rc1 or >= v1.1.1, <= v1.1.1 or >= v1.1.0, <= v1.1.0 or >= v1.0.0, <= v1.0.0 or >= v0.2.6, <= v0.2.6 or >= v0.2.5, <= v0.2.5 or >= v0.2.4, <= v0.2.4 or >= v0.2.3, <= v0.2.3 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.1, <= v0.1.1 or >= v0.1.0, <= v0.1.0
Patched version
Not yet available
CVE-2026-85663

The Aim npm package versions from v0.1.0 to v3.29.1 contain a critical authentication flaw allowing unauthenticated access. Users of these versions are affected.

What happened

The Aim npm package, versions from v0.1.0 to v3.29.1, has been confirmed to have a critical vulnerability. This flaw allows unauthenticated attackers to register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs. The vulnerability was first flagged on September 4, 2026, and confirmed on September 8, 2026. The flaw has a CVSS score of 9.8, indicating a critical severity level.

To assess your exposure, check if your project dependencies include any version of Aim within the affected range. If so, you are vulnerable to this authentication bypass attack.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If aim is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your project uses Aim npm package versions from v0.1.0 to v3.29.1.

What should I do right now?

Immediately identify and upgrade any instances of Aim in your project to a version that includes proper authentication and method validation. Monitor primary sources for updates on a patched version.

Is there a patched version available?

No official patched version has been published yet. Continue to monitor primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats