CVE-2025-49651: Lablup Backendai

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists in all current versions of BackendAI.

Affected products

Published 2025-06-09. Last modified 2026-06-17.