CVE-2026-53656: CWE-346: Origin Validation Error in voxel51 fiftyone
FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/server/routes/media.py unconditionally return Access-Control-Allow-Origin: *. Because the embedded server is local and unauthenticated, a malicious website visited by the user can read cross-origin responses. The /media endpoint accepts a filesystem path, allowing a drive-by page to read files accessible to the server process and exfiltrate them without additional clicks. The allowed_origins configuration and FIFTYONE_ALLOWED_ORIGINS environment variable now make cross-origin access explicit, while the default policy is same-origin. This issue is fixed in version 1.17.0.
AI Analysis
Technical Summary
The FiftyOne App/API server in versions before 1.17.0 unconditionally returns Access-Control-Allow-Origin: * headers, enabling any website visited by the user to perform cross-origin reads of local server data. The /media endpoint accepts a filesystem path parameter, which can be exploited by a malicious webpage to read arbitrary files accessible to the server process and exfiltrate their contents without further user interaction. The vulnerability arises from improper CORS configuration and lack of authentication on the embedded local server. The issue is resolved in version 1.17.0 by introducing the allowed_origins configuration option and the FIFTYONE_ALLOWED_ORIGINS environment variable, which restrict cross-origin access to explicit origins and default to a same-origin policy.
Potential Impact
An attacker can exploit this vulnerability by tricking a user into visiting a malicious website, which can then read sensitive local files served by the FiftyOne App's /media endpoint via cross-origin requests. This leads to confidentiality loss of local data accessible to the server process. The vulnerability does not allow modification or denial of service but can expose high-value local files without user consent beyond visiting the malicious page.
Mitigation Recommendations
This vulnerability is fixed in FiftyOne App version 1.17.0. Users should upgrade to version 1.17.0 or later to ensure cross-origin access is properly restricted. The fix introduces explicit allowed_origins configuration and environment variables to control CORS policies, defaulting to same-origin. No additional mitigation is required once upgraded.
CVE-2026-53656: CWE-346: Origin Validation Error in voxel51 fiftyone
Description
FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/server/routes/media.py unconditionally return Access-Control-Allow-Origin: *. Because the embedded server is local and unauthenticated, a malicious website visited by the user can read cross-origin responses. The /media endpoint accepts a filesystem path, allowing a drive-by page to read files accessible to the server process and exfiltrate them without additional clicks. The allowed_origins configuration and FIFTYONE_ALLOWED_ORIGINS environment variable now make cross-origin access explicit, while the default policy is same-origin. This issue is fixed in version 1.17.0.
CVSS v3.1
Score 6.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The FiftyOne App/API server in versions before 1.17.0 unconditionally returns Access-Control-Allow-Origin: * headers, enabling any website visited by the user to perform cross-origin reads of local server data. The /media endpoint accepts a filesystem path parameter, which can be exploited by a malicious webpage to read arbitrary files accessible to the server process and exfiltrate their contents without further user interaction. The vulnerability arises from improper CORS configuration and lack of authentication on the embedded local server. The issue is resolved in version 1.17.0 by introducing the allowed_origins configuration option and the FIFTYONE_ALLOWED_ORIGINS environment variable, which restrict cross-origin access to explicit origins and default to a same-origin policy.
Potential Impact
An attacker can exploit this vulnerability by tricking a user into visiting a malicious website, which can then read sensitive local files served by the FiftyOne App's /media endpoint via cross-origin requests. This leads to confidentiality loss of local data accessible to the server process. The vulnerability does not allow modification or denial of service but can expose high-value local files without user consent beyond visiting the malicious page.
Mitigation Recommendations
This vulnerability is fixed in FiftyOne App version 1.17.0. Users should upgrade to version 1.17.0 or later to ensure cross-origin access is properly restricted. The fix introduces explicit allowed_origins configuration and environment variables to control CORS policies, defaulting to same-origin. No additional mitigation is required once upgraded.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-q78p-hj9h-5466
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53656"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a58b41468715ace43d68327
Added to database: 07/16/2026, 10:36:04 UTC
Last enriched: 08/22/2026, 11:07:21 UTC
Last updated: 08/31/2026, 20:46:41 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.