backend-ai vulnerabilities
CVEs whose affected-version data names the backend-ai package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-49653High· 8.0BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
▾ Twilightbackend-ai · backend-aiEPSS 0.35%via OSV
CVE-2025-49651High· 8.1Backend.AI Missing Authorization vulnerability
Backend.AI Missing Authorization vulnerability
▾ Twilightbackend-ai · backend-aiEPSS 0.34%via OSV