CVE-2025-25302 affects Rembg versions 2.0.57 and earlier, a tool for image background removal. The vulnerability stems from an improperly configured Cross-Origin Resource Sharing (CORS) middleware, which reflects all origins. This misconfiguration allows any website to send cross-site requests to the Rembg server, potentially querying any API, and even sending authenticated requests if authentication were enabled due to allow_credentials being set to True. The vulnerability is rated Medium with a CVSS score of 6.5, indicating a network-based attack with low attack complexity and no user interaction required. It poses a risk of low impact to confidentiality and integrity (C:L/I:L), as unauthorized access to APIs and data could occur. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has garnered minimal community discussion and media coverage, suggesting a low level of public awareness or immediate concern regarding its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.57CPE matchmatch criteria | cpe:2.3:a:danielgatis:rembg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.