PT-2025-9519 · Rembg · Rembg

Kevin Stubbings

+1

·

Published

2025-03-03

·

Updated

2025-03-11

·

CVE-2025-25301

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rembg versions 2.0.57 and earlier
Description The issue allows an attacker to query the "/api/remove" endpoint to view pictures hosted on the internal network of the Rembg server, potentially leading to Information Disclosure. This is achieved by exploiting the URL query parameter in the endpoint.
Recommendations For Rembg versions 2.0.57 and earlier, consider disabling access to the "/api/remove" endpoint until a patch is available to prevent potential information disclosure. Restrict access to internal network resources to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-25301
GHSA-R5GX-C49X-H878
PYSEC-2025-24

Affected Products

Rembg