Danielgatis maintains a focused image-processing tool, rembg, which automates background removal from photographs and has found adoption in document-processing and media-editing pipelines. The observed vulnerability surface clusters around input-handling and request-validation weaknesses, including path traversal, external file-name control, origin validation errors, and server-side request forgery, reflecting the product's role in accepting and transforming user-supplied media. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Danielgatis over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40086MEDIUM Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary file | Apr 10, 2026 | 5.3 | 20 | NO | NO |
CVE-2025-25302MEDIUM Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cros | Mar 3, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-25301HIGH Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and ret | Mar 3, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Danielgatis.
Media articles that mention a CVE ID that affects a product developed by Danielgatis — matched by CVE ID, not by vendor name.