CVE-2025-25301

HIGH

rembg < 2.0.57 - Server-Side Request Forgery via /api/remove URL Parameter

Title source: llm
STIX 2.1

Description

Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://securitylab.github.com/advisories/GHSL-2024-161_GHSL-2024-162_rembg/

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 13.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
danielgatis/rembg < 2.0.57
pypi/rembg 0PyPI
Published Mar 03, 2025
Tracked Since Feb 18, 2026