rembg@2.0.50 vulnerabilities

Remove image background

Direct Vulnerabilities

Known vulnerabilities in the rembg package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Server-side Request Forgery (SSRF)

rembg is a Remove image background

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the /api/remove endpoint, which takes a URL query parameter to fetch, process, and return images. An attacker can access pictures hosted on the internal network of the server.

How to fix Server-side Request Forgery (SSRF)?

There is no fixed version for rembg.

[0,)
  • H
Origin Validation Error

rembg is a Remove image background

Affected versions of this package are vulnerable to Origin Validation Error in the add_middleware() function in s_command.py, which reflects all origins by default. Due to the allow_credentials=True setting, an attacker can send authenticated cross-site requests and access unintended APIs.

How to fix Origin Validation Error?

There is no fixed version for rembg.

[0,)