backend.ai
Lablup Backend.AI Meta-package
Activity
- Latest release
- 4y ago
- Total releases
- 17
- Cadence
- ~3 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- LGPL-3.0
- First release
- Sep 06, 2017
| Version | Released | |
|---|---|---|
22.3.0
major
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
21.3.0
major
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
20.9.0
minor
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
20.9.0a1.dev0
pre
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
20.3.1
patch
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
20.3.0
major
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
19.9.0
minor
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev |
19.9.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
19.3.0
major
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
19.3.0a1
pre
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev |
19.3.0a1
pre
Dependencies (8)
Changelog
Compare changes
|
|
18.12.0
major
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.4.0
minor
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.3.0
minor
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.2.0
minor
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.1.0
minor
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.0.2
patch
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.0.1
patch
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.0.0
initial
3 CVEs
CVE-2025-49651
PYSEC-2026-1210
GHSA-h889-475r-wfmm
Jul 07, 2026
Backend.AI Missing Authorization vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49653
PYSEC-2026-1211
GHSA-hxvr-gg2w-j48x
Jul 07, 2026
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. NOTE: The maintainers of BackendAI do not consider this report to fit with their threat model and advise users to follow security advice from https://github.com/lablup/backend.ai/pull/7587 in their instances to protect themselves from the conditions that would lead to the situation described in the CVE record. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49652
PYSEC-2026-290
GHSA-ww28-4m4v-cq4j
Jun 29, 2026
BackendAI Missing Authentication for Critical Function
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled. Affected versions
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
18.12.0
19.3.0
19.3.0a1
19.9.0
20.3.0
+ 5 more Show less
20.3.1
20.9.0
20.9.0a1.dev0
21.3.0
22.3.0
Fixed in
25.15.6
25.19.0rc1
References
Updated Jul 02, 2026 · Source: OSV.dev |