Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. rembg
  4. ›
  5. CVE-2025-25302

CVE-2025-25302: Rembg CORS misconfiguration

March 11, 2025

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.

References

  • github.com/advisories/GHSA-59qh-fmm7-3g9q
  • github.com/danielgatis/rembg
  • github.com/danielgatis/rembg/blob/d1e00734f8a996abf512a3a5c251c7a9a392c90a/rembg/commands/s_command.py
  • nvd.nist.gov/vuln/detail/CVE-2025-25302
  • securitylab.github.com/advisories/GHSL-2024-161_GHSL-2024-162_rembg

Code Behaviors & Features

Detect and mitigate CVE-2025-25302 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.0.57

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-346: Origin Validation Error

Source file

pypi/rembg/CVE-2025-25302.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:49 +0000.