Aller au contenu

Fiche vulnérabilité

CVE-2025-25301 : faille élevée danielgatis rembg (CVSS 7.5)

Description

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
3 mars 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • danielgatis rembg

Références

Rechercher une autre vulnérabilité dans la base CVE