---
id: CVE-2025-55795
title: >-
  The openml/openml.org web application version v2.0.20241110 uses incremental
  user IDs and insufficient email ownership verification during email update
  workflows
summary: >-
  The openml/openml.org web application version v2.0.20241110 uses incremental
  user IDs and insufficient email ownership verification during email update
  workflows. An authenticated attacker controlling a user account with a lower
  user ID …
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-284
  - CWE-639
vendor: openml
product: openml_frontend
affected:
  - openml_frontend < 2.0.20251111
patched:
  - openml_frontend 2.0.20251111
published: '2025-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:41:30.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55795'
references:
  - url: 'https://github.com/openml'
    label: cve@mitre.org
  - url: 'https://github.com/openml/openml.org'
    label: cve@mitre.org
  - url: >-
      https://github.com/openml/openml.org/security/advisories/GHSA-87c5-mc8v-xf7r
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00301
epssPercentile: 0.20538
ingestedAt: '2026-09-29T16:39:33.222Z'
---

## Overview

The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a higher user ID without proper verification. This results in the victim's email being reassigned to the attacker's account, causing the victim to be locked out immediately and unable to log in. The vulnerability leads to denial of service via account lockout but does not grant the attacker direct access to the victim's private data.

## Affected

- `openml_frontend < 2.0.20251111`

## Remediation

Upgrade past the affected range:

- `openml_frontend 2.0.20251111`
