{"package":"rembg","ecosystem":"conda","latest_version":"2.0.53","description":"Remove image background","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://pypi.org/project/rembg","repository":"https://github.com/danielgatis/rembg","downloads_weekly":57,"health":{"score":20,"risk":"critical","breakdown":{"maintenance":5,"popularity":0,"security":7,"maturity":6,"community":2},"deprecated":false,"max_score":100},"vulnerabilities":{"count":6,"critical":0,"high":2,"medium":4,"low":0,"details":[{"vuln_id":"CVE-2026-40086","severity":"medium","summary":"Rembg has a Path Traversal via Custom Model Loading","affected_versions":"<2.0.75|=2.0.28|=2.0.29|=2.0.30|=2.0.31|=2.0.32|=2.0.33|=2.0.34|=2.0.35|=2.0.36|=2.0.37|=2.0.38|=2.0.39|=2.0.40|=2.0.41|=2.0.43|=2.0.44|=2.0.45|=2.0.46|=2.0.47|=2.0.48|=2.0.49|=2.0.50|=2.0.51|=2.0.52|=2.0.53|=2.0.54|=2.0.55|=2.0.56|=2.0.57|=2.0.58|=2.0.59|=2.0.60|=2.0.61|=2.0.62|=2.0.63|=2.0.64|=2.0.65|=2.0.66|=2.0.67|=2.0.68|=2.0.69|=2.0.70|=2.0.71|=2.0.72|=2.0.73|=2.0.74","fixed_version":"2.0.75","source":"osv","published_at":"2026-04-10T20:00:12Z","in_kev":false,"epss_prob":0.0005,"epss_percentile":0.15469,"threat_tier":"theoretical"},{"vuln_id":"GHSA-55v6-g8pm-pw4c","severity":"medium","summary":"rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration","affected_versions":"<2.0.75|=2.0.28|=2.0.29|=2.0.30|=2.0.31|=2.0.32|=2.0.33|=2.0.34|=2.0.35|=2.0.36|=2.0.37|=2.0.38|=2.0.39|=2.0.40|=2.0.41|=2.0.43|=2.0.44|=2.0.45|=2.0.46|=2.0.47|=2.0.48|=2.0.49|=2.0.50|=2.0.51|=2.0.52|=2.0.53|=2.0.54|=2.0.55|=2.0.56|=2.0.57|=2.0.58|=2.0.59|=2.0.60|=2.0.61|=2.0.62|=2.0.63|=2.0.64|=2.0.65|=2.0.66|=2.0.67|=2.0.68|=2.0.69|=2.0.70|=2.0.71|=2.0.72|=2.0.73|=2.0.74","fixed_version":"2.0.75","source":"osv","published_at":"2026-04-10T22:09:15Z","in_kev":false,"threat_tier":"unknown"},{"vuln_id":"CVE-2025-25302","severity":"high","summary":"Rembg CORS misconfiguration","affected_versions":"<=2.0.57|=2.0.28|=2.0.29|=2.0.30|=2.0.31|=2.0.32|=2.0.33|=2.0.34|=2.0.35|=2.0.36|=2.0.37|=2.0.38|=2.0.39|=2.0.40|=2.0.41|=2.0.43|=2.0.44|=2.0.45|=2.0.46|=2.0.47|=2.0.48|=2.0.49|=2.0.50|=2.0.51|=2.0.52|=2.0.53|=2.0.54|=2.0.55|=2.0.56|=2.0.57","fixed_version":null,"source":"osv","published_at":"2025-03-11T21:32:43Z","in_kev":false,"epss_prob":0.00042,"epss_percentile":0.12549,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-25301","severity":"medium","summary":"Rembg allows SSRF via /api/remove","affected_versions":"<=2.0.57|=2.0.28|=2.0.29|=2.0.30|=2.0.31|=2.0.32|=2.0.33|=2.0.34|=2.0.35|=2.0.36|=2.0.37|=2.0.38|=2.0.39|=2.0.40|=2.0.41|=2.0.43|=2.0.44|=2.0.45|=2.0.46|=2.0.47|=2.0.48|=2.0.49|=2.0.50|=2.0.51|=2.0.52|=2.0.53|=2.0.54|=2.0.55|=2.0.56|=2.0.57","fixed_version":null,"source":"osv","published_at":"2025-03-11T21:31:01Z","in_kev":false,"epss_prob":0.00044,"epss_percentile":0.13251,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-25301","severity":"high","summary":"Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.","affected_versions":"<2.0.58|=2.0.28|=2.0.29|=2.0.30|=2.0.31|=2.0.32|=2.0.33|=2.0.34|=2.0.35|=2.0.36|=2.0.37|=2.0.38|=2.0.39|=2.0.40|=2.0.41|=2.0.43|=2.0.44|=2.0.45|=2.0.46|=2.0.47|=2.0.48|=2.0.49|=2.0.50|=2.0.51|=2.0.52|=2.0.53|=2.0.54|=2.0.55|=2.0.56|=2.0.57","fixed_version":"2.0.58","source":"osv","published_at":"2025-03-03T17:15:14Z","in_kev":false,"epss_prob":0.00044,"epss_percentile":0.13251,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-25302","severity":"medium","summary":"Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All origins are reflected, which allows any website to send cross site requests to the rembg server and thus query any API. Even if authentication were to be enabled, allow_credentials is set to True, which would allow any website to send authenticated cross site requests.","affected_versions":"<2.0.58|=2.0.28|=2.0.29|=2.0.30|=2.0.31|=2.0.32|=2.0.33|=2.0.34|=2.0.35|=2.0.36|=2.0.37|=2.0.38|=2.0.39|=2.0.40|=2.0.41|=2.0.43|=2.0.44|=2.0.45|=2.0.46|=2.0.47|=2.0.48|=2.0.49|=2.0.50|=2.0.51|=2.0.52|=2.0.53|=2.0.54|=2.0.55|=2.0.56|=2.0.57","fixed_version":"2.0.58","source":"osv","published_at":"2025-03-03T17:15:14Z","in_kev":false,"epss_prob":0.00042,"epss_percentile":0.12549,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"2.0.53","total_count":3,"recent":["2.0.51","2.0.52","2.0.53"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":1,"first_published":"2023-10-27 20:30:10.177000+00:00","last_published":"2025-04-22 14:58:50.292000+00:00","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"update_required","issues":["Low health score (20/100)","2 high severity vulnerabilities"],"use_version":"2.0.53","version_hint":"Update to >= 2.0.58 to fix known vulnerabilities","summary":"rembg@2.0.53 has vulnerabilities — update to latest"},"version_scoped":null,"requested_version":null,"_cache":"miss","_response_ms":582,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":3,"first_release_age_days":917,"last_release_days_ago":374,"avg_days_between_releases":458,"release_velocity":"stale"},"popularity_warning":{"this_ecosystem_downloads":57,"more_popular_in":{"ecosystem":"pypi","downloads_weekly":540958},"hint":"This is the conda package 'rembg' (57 dl/week). A much more popular package with the same name exists in pypi (540,958 dl/week). Confirm you queried the right ecosystem."}}