{"id":"PYSEC-2026-290","summary":"BackendAI Missing Authentication for Critical Function","details":"Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.","aliases":["CVE-2025-49652","GHSA-ww28-4m4v-cq4j"],"modified":"2026-07-01T20:22:49.653897Z","published":"2026-06-29T11:50:38.333670Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49652"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983"},{"type":"PACKAGE","url":"https://github.com/lablup/backend.ai"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-06-backendai"},{"type":"PACKAGE","url":"https://pypi.org/project/backend-ai"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-ww28-4m4v-cq4j"}],"affected":[{"package":{"name":"backend-ai","ecosystem":"PyPI","purl":"pkg:pypi/backend-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"25.16.0rc1"},{"fixed":"25.19.0rc1"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/backend-ai/PYSEC-2026-290.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}