CVE-2025-49653 HIGH

CVE-2025-49653: Exposure of sensitive Information allows account takeover

Vendor Lablup
Product BackendAI
Weakness CWE-200 · Info exposure
Published June 9, 2025
Last update June 11, 2025

CVSS base score

8.0/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.

Key dates

02Disclosure timeline

June 9, 2025 CVE published
June 11, 2025 Record updated