CVE-2025-49652: Lablup Backendai

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.

Affected products

Published 2025-06-09. Last modified 2026-06-17.