CVE-2025-25302
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.19%
- CWE
- CWE-346
- Published
- 2025-03-03
- Last modified
- 2026-03-12
Affected products
- danielgatis rembg
Weakness type
Related vulnerabilities
- CVE-2026-87563 — Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-58649 — .NET Information Disclosure Vulnerability
- CVE-2026-69559 — Microsoft Teams for Android Information Disclosure Vulnerability
- CVE-2026-69680 — Windows DNS Spoofing Vulnerability
- CVE-2026-75156 — Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
- CVE-2026-85152 — undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
- CVE-2026-84482 — WWBN AVideo Cross-Site Request Forgery via get_domain() validation
- CVE-2026-82811 — Toggl OÜ Toggl Track Extension postMessage origin validation