© 2025-2026 PySpect
First version without a known vulnerability: 2.0.75
rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration
Fixed in: 2.0.75
Rembg has a Path Traversal via Custom Model Loading
Fixed in: 2.0.75
Rembg CORS misconfiguration
Fixed in: 2.0.58
Rembg allows SSRF via /api/remove
Fixed in: 2.0.58