CRITICAL 9.8
PYSEC-2026-290
BackendAI Missing Authentication for Critical Function
Details
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / backend-ai
Introduced in:
0 Fixed in: 25.15.6 Fix
pip install --upgrade 'backend-ai>=25.15.6' References
- https://nvd.nist.gov/vuln/detail/CVE-2025-49652 [ADVISORY]
- https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed [WEB]
- https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f [WEB]
- https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983 [WEB]
- https://github.com/lablup/backend.ai [PACKAGE]
- https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653 [WEB]
- https://hiddenlayer.com/sai_security_advisor/2025-06-backendai [WEB]
- https://pypi.org/project/backend-ai [PACKAGE]
- https://github.com/advisories/GHSA-ww28-4m4v-cq4j [ADVISORY]