-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability occurs when a remote tracking server is configured to point to itself. The Repo class constructor (init) handles 'aim://' URIs by creating a Client and RemoteRepoProxy without checking if the target is the local instance. This allows circular connections where the server connects to itself, creating an unreachable loop condition. The code at line 195 in repo.py initiates this remote connection setup without validation mechanisms to prevent self-referential configurations.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| aim | pip | <= 3.19.3 |
Ongoing coverage of React2Shell