CVE-2025-49652
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-49652, https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed, https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f, https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983, https://github.com/lablup/backend.ai, https://hiddenlayer.com/saisecurityadvisor/2025-05-backendai-49653, https://hiddenlayer.com/saisecurityadvisor/2025-06-backendai, https://pypi.org/project/backend-ai, https://github.com/advisories/GHSA-ww28-4m4v-cq4j