Safety vulnerability ID: 76310
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is set up incorrectly. All origins are reflected, which allows any website to send cross-site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross-site requests.
Latest version: 2.0.65
Remove image background
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application