CRITICAL 9.8 PyPI
BackendAI Missing Authentication for Critical Function
GHSA-ww28-4m4v-cq4j · CVE-2025-49652 · PYSEC-2026-290
Published · Modified
Description
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-49652
- WEB https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed
- WEB https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f
- WEB https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983
- PACKAGE https://github.com/lablup/backend.ai
- WEB https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653
- WEB https://hiddenlayer.com/sai_security_advisor/2025-06-backendai
Ready to move
Start Securing
Free, no credit card | First findings in minutes