Логотип exploitDog
bind:CVE-2025-25301
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-25301

Количество 2

Количество 2

nvd логотип

CVE-2025-25301

11 месяцев назад

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r5gx-c49x-h878

11 месяцев назад

Rembg allows SSRF via /api/remove

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-25301

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-r5gx-c49x-h878

Rembg allows SSRF via /api/remove

CVSS3: 7.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу