CVE-2026-53656: FiftyOne: wildcard CORS enables local file exfiltration

GHSA-q78p-hj9h-5466 MEDIUM
Published July 15, 2026
CISO Take

FiftyOne, the popular open-source tool for visualizing and curating ML datasets, hard-codes a wildcard `Access-Control-Allow-Origin: *` header on its local, unauthenticated App/API server and its `/media` file-read endpoint, meaning any website a data scientist merely has open in the background can silently read files off their machine — no clicks required beyond the page load. With 2,957 downstream dependents and a package risk score of 32/100 reflecting 20 prior CVEs in the same codebase, this sits on a meaningful slice of ML engineering workstations, and the `/media?filepath=` parameter can pull SSH keys, cloud credentials, `.env` files, or proprietary dataset media straight through a browser's usual same-origin protections. There is no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template yet, so this is not a same-day fire drill, but the drive-by mechanics — Safari and Firefox still don't enforce Private Network Access protections against local servers — make it a live risk for anyone running FiftyOne locally while browsing normally. Upgrade to FiftyOne 1.17.0, which defaults to same-origin CORS and requires explicit opt-in via `FIFTYONE_ALLOWED_ORIGINS` for any cross-origin use; until then, don't run the App server while browsing untrusted sites and confirm it stays bound to localhost only.

Sources: NVD GitHub Advisory OWASP ATLAS OpenSSF

What is the risk?

CVSS 3.1 base score 6.3 (medium): AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N — a local attack vector with changed scope (the browser acts as a confused deputy crossing into the local server's trust boundary) and high confidentiality impact but no integrity or availability effect. Exploitability is trivial from an attacker's perspective — a single cross-origin `fetch()` call in any web page's JavaScript — but requires user interaction in the form of simply visiting a page while the FiftyOne server happens to be running. No EPSS score, no CISA KEV entry, and no public PoC or Nuclei template currently exist, so real-world exploitation likelihood is unconfirmed and probably low-volume rather than mass-scanned; however, the vulnerability class (wildcard CORS + unauthenticated local file read) is well understood offensive tradecraft, and any future ad-network or watering-hole compromise could weaponize it broadly against the FiftyOne user base without new research.

How does the attack unfold?

Initial Access
Victim with a local FiftyOne App server running visits a malicious or compromised web page; no click or additional interaction is needed.
AML.T0078
Exploitation
The page's background JavaScript sends a cross-origin request to the local FiftyOne server's /media endpoint with an arbitrary filepath, and the wildcard CORS header lets the script read the response.
AML.T0037
Exfiltration
The script forwards the stolen file contents (SSH keys, cloud credentials, .env files, or dataset media) to an attacker-controlled server via a normal outbound web request.
AML.T0025
Impact
Stolen credentials enable follow-on compromise of cloud infrastructure or CI systems, while leaked dataset media exposes proprietary training data.
AML.T0048.004

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook pip < 1.17.0 1.17.0
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
6.3 / 10
EPSS
0.1%
chance of exploitation in 30 days
Higher than 2% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Local
AC Low
PR None
UI Required
S Changed
C High
I None
A None

What should I do?

1 step
  1. Upgrade to FiftyOne 1.17.0 or later, which removes the hard-coded wildcard CORS header and defaults to same-origin-only responses (cross-origin access becomes explicit opt-in via FIFTYONE_ALLOWED_ORIGINS, including a * escape hatch that logs a warning if truly needed). Until upgraded: never leave the FiftyOne App server running while browsing untrusted websites, keep it bound to localhost (the default — do not expose it on a network interface), and prefer a browser that enforces Private Network Access protections (Chromium 142+); Safari and Firefox do not yet block this. For detection, review FiftyOne server access logs for /media requests carrying unexpected Origin headers, and monitor ML workstation egress for connections to unfamiliar domains coincident with FiftyOne usage.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.6.2.6 - AI system security
NIST AI RMF
MANAGE-4.1 - Risk monitoring and response for deployed AI systems and components

Frequently Asked Questions

What is CVE-2026-53656?

FiftyOne, the popular open-source tool for visualizing and curating ML datasets, hard-codes a wildcard `Access-Control-Allow-Origin: *` header on its local, unauthenticated App/API server and its `/media` file-read endpoint, meaning any website a data scientist merely has open in the background can silently read files off their machine — no clicks required beyond the page load. With 2,957 downstream dependents and a package risk score of 32/100 reflecting 20 prior CVEs in the same codebase, this sits on a meaningful slice of ML engineering workstations, and the `/media?filepath=` parameter can pull SSH keys, cloud credentials, `.env` files, or proprietary dataset media straight through a browser's usual same-origin protections. There is no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template yet, so this is not a same-day fire drill, but the drive-by mechanics — Safari and Firefox still don't enforce Private Network Access protections against local servers — make it a live risk for anyone running FiftyOne locally while browsing normally. Upgrade to FiftyOne 1.17.0, which defaults to same-origin CORS and requires explicit opt-in via `FIFTYONE_ALLOWED_ORIGINS` for any cross-origin use; until then, don't run the App server while browsing untrusted sites and confirm it stays bound to localhost only.

Is CVE-2026-53656 actively exploited?

No confirmed active exploitation of CVE-2026-53656 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-53656?

Upgrade to FiftyOne 1.17.0 or later, which removes the hard-coded wildcard CORS header and defaults to same-origin-only responses (cross-origin access becomes explicit opt-in via `FIFTYONE_ALLOWED_ORIGINS`, including a `*` escape hatch that logs a warning if truly needed). Until upgraded: never leave the FiftyOne App server running while browsing untrusted websites, keep it bound to `localhost` (the default — do not expose it on a network interface), and prefer a browser that enforces Private Network Access protections (Chromium 142+); Safari and Firefox do not yet block this. For detection, review FiftyOne server access logs for `/media` requests carrying unexpected `Origin` headers, and monitor ML workstation egress for connections to unfamiliar domains coincident with FiftyOne usage.

What systems are affected by CVE-2026-53656?

This vulnerability affects the following AI/ML architecture patterns: training data pipelines, dataset curation/visualization tooling, local ML developer workstations, MLOps tooling.

What is the CVSS score for CVE-2026-53656?

CVE-2026-53656 has a CVSS v3.1 base score of 6.3 (MEDIUM). The EPSS exploitation probability is 0.12%.

What is the AI security impact?

Affected AI Architectures

training data pipelinesdataset curation/visualization toolinglocal ML developer workstationsMLOps tooling

MITRE ATLAS Techniques

AML.T0025 Exfiltration via Cyber Means
AML.T0037 Data from Local System
AML.T0078 Drive-by Compromise

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.6
NIST AI RMF: MANAGE-4.1

What are the technical details?

Original Advisory

FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/server/routes/media.py unconditionally return Access-Control-Allow-Origin: *. Because the embedded server is local and unauthenticated, a malicious website visited by the user can read cross-origin responses. The /media endpoint accepts a filesystem path, allowing a drive-by page to read files accessible to the server process and exfiltrate them without additional clicks. The allowed_origins configuration and FIFTYONE_ALLOWED_ORIGINS environment variable now make cross-origin access explicit, while the default policy is same-origin. This issue is fixed in version 1.17.0.

Exploitation Scenario

An attacker compromises an ad network, a niche technical forum, or sends a phishing link to an ML engineer who has FiftyOne's App server running locally (a common background state during dataset labeling sessions). The malicious page's JavaScript issues a background cross-origin request to `http://localhost:5151/media?filepath=/Users/victim/.ssh/id_rsa` (or `/etc/passwd`, a cloud `credentials` file, or a project `.env`). Because the server unconditionally sends `Access-Control-Allow-Origin: *`, the browser permits the malicious page's script to read the response body despite the origin mismatch. The script then relays the stolen file contents to an attacker-controlled endpoint via a second outbound request — the entire exfiltration completes silently while the victim continues browsing normally, with no visible indicator on either the malicious page or the FiftyOne UI.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Timeline

Published
July 15, 2026
Last Modified
August 21, 2026
First Seen
July 16, 2026

Related Vulnerabilities