Vulnerability Description
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Danielgatis | Rembg | <= 2.0.57 |
Related Weaknesses (CWE)
References
- https://securitylab.github.com/advisories/GHSL-2024-161_GHSL-2024-162_rembg/ExploitThird Party Advisory
FAQ
What is CVE-2025-25301?
CVE-2025-25301 is a vulnerability with a CVSS score of 7.5 (HIGH). Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker m...
How severe is CVE-2025-25301?
CVE-2025-25301 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25301?
Check the references section above for vendor advisories and patch information. Affected products include: Danielgatis Rembg.