OVERVIEW CVE-2026-40086 is a path traversal vulnerability in the rembg background removal tool affecting versions prior to 2.0.75. The flaw exists in the HTTP server component and allows unauthenticated remote attackers to read arbitrary files from the server filesystem by manipulating the model_path parameter with crafted requests. The vulnerability has been resolved in version 2.0.75. SEVERITY This vulnerability presents a low-to-medium risk profile with a CVSS v3.1 score of 5.3. The attack vector is network-based with low complexity, requiring no authentication or user interaction. The primary impact is limited to confidentiality, as attackers can disclose file existence, filesystem permissions, and potentially file contents through error messages. Integrity and availability are not affected. The exploitation difficulty is minimal given the straightforward attack method. EXPLOITATION STATUS There is no indication of active exploitation in the wild. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities (KEV) catalog and is currently inactive on threat intelligence hot lists. Public exploit code availability is not noted. While the technical barrier to exploitation is low, the limited community attention and absence of exploitation reports suggest this remains a theoretical risk at present. Organizations should prioritize patching to version 2.0.75 as a preventive measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.75CPE matchmatch criteria | cpe:2.3:a:danielgatis:rembg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.