Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danielgatis
Danielgatis rembg |
|
| CPEs | cpe:2.3:a:danielgatis:rembg:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Danielgatis
Danielgatis rembg |
|
| Metrics |
cvssV3_1
|
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests. | |
| Title | Rembg CORS misconfiguration | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-03T16:40:34.811Z
Updated: 2025-03-03T17:55:31.580Z
Reserved: 2025-02-06T17:13:33.123Z
Link: CVE-2025-25302
Updated: 2025-03-03T17:55:26.015Z
Status : Analyzed
Published: 2025-03-03T17:15:14.920
Modified: 2025-03-21T13:35:46.543
Link: CVE-2025-25302
No data.