Cross-Origin Resource Sharing Flaw in FiftyOne Open-Source Platform
CVE-2026-53656
6.3MEDIUM
What is CVE-2026-53656?
The FiftyOne platform, an open-source tool for managing datasets and visual AI models, contains a security flaw prior to version 1.17.0. This vulnerability allows unregulated Access-Control-Allow-Origin headers to be returned by the platform, making it susceptible to cross-origin attacks. A malicious site could leverage this flaw, enabling it to access sensitive information from the FiftyOne server through its /media route. Additionally, the endpoint in question permits direct filesystem path access, increasing the risk of data exfiltration without user consent. The issue has been addressed in version 1.17.0, which now enforces explicit cross-origin access controls.
Affected Version(s)
fiftyone < 1.16.1
