{"id":"CVE-2025-49652","aliases":["PYSEC-2026-290"],"url":"https://o3.security/vulnerability/CVE-2025-49652","summary":"BackendAI Missing Authentication for Critical Function","details":"Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.","published":"2025-06-09T18:32:17Z","modified":"2026-06-29T12:26:20.422884134Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"backend-ai","fixedVersion":"25.15.6"},{"ecosystem":"PyPI","name":"backend-ai","fixedVersion":"25.19.0rc1"}],"fix":{"url":"https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed","label":"lablup/backend.ai@37fc8f7"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49652"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983"},{"type":"PACKAGE","url":"https://github.com/lablup/backend.ai"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-06-backendai"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T12:26:20.422884134Z"}}