HIGH7.5PyPI
PYSEC-2025-24· CVE-2025-25301, GHSA-r5gx-c49x-h878Modified: 6/10/2026
package
pkg:pypi/rembg
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 7/13/2026
Rembg has a Path Traversal via Custom Model Loading
Modified: 7/13/2026
rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration
Modified: 4/10/2026
Rembg CORS misconfiguration
Modified: 4/9/2025
Rembg allows SSRF via /api/remove
Modified: 4/9/2025