Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Danielgatis
Danielgatis rembg |
|
CPEs | cpe:2.3:a:danielgatis:rembg:*:*:*:*:*:*:*:* | |
Vendors & Products |
Danielgatis
Danielgatis rembg |
|
Metrics |
cvssV3_1
|
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests. | |
Title | Rembg CORS misconfiguration | |
Weaknesses | CWE-346 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-03T17:55:31.580Z
Reserved: 2025-02-06T17:13:33.123Z
Link: CVE-2025-25302

Updated: 2025-03-03T17:55:26.015Z

Status : Analyzed
Published: 2025-03-03T17:15:14.920
Modified: 2025-03-21T13:35:46.543
Link: CVE-2025-25302

No data.