FiftyOne, the popular open-source tool for visualizing and curating ML datasets, hard-codes a wildcard `Access-Control-Allow-Origin: *` header on its local, unauthenticated App/API server and its `/media` file-read endpoint, meaning any website a data scientist merely has open in the background can silently read files off their machine — no clicks required beyond the page load. With 2,957 downstream dependents and a package risk score of 32/100 reflecting 20 prior CVEs in the same codebase, this sits on a meaningful slice of ML engineering workstations, and the `/media?filepath=` parameter can pull SSH keys, cloud credentials, `.env` files, or proprietary dataset media straight through a browser's usual same-origin protections. There is no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template yet, so this is not a same-day fire drill, but the drive-by mechanics — Safari and Firefox still don't enforce Private Network Access protections against local servers — make it a live risk for anyone running FiftyOne locally while browsing normally. Upgrade to FiftyOne 1.17.0, which defaults to same-origin CORS and requires explicit opt-in via `FIFTYONE_ALLOWED_ORIGINS` for any cross-origin use; until then, don't run the App server while browsing untrusted sites and confirm it stays bound to localhost only.
What is the risk?
CVSS 3.1 base score 6.3 (medium): AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N — a local attack vector with changed scope (the browser acts as a confused deputy crossing into the local server's trust boundary) and high confidentiality impact but no integrity or availability effect. Exploitability is trivial from an attacker's perspective — a single cross-origin `fetch()` call in any web page's JavaScript — but requires user interaction in the form of simply visiting a page while the FiftyOne server happens to be running. No EPSS score, no CISA KEV entry, and no public PoC or Nuclei template currently exist, so real-world exploitation likelihood is unconfirmed and probably low-volume rather than mass-scanned; however, the vulnerability class (wildcard CORS + unauthenticated local file read) is well understood offensive tradecraft, and any future ad-network or watering-hole compromise could weaponize it broadly against the FiftyOne user base without new research.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | pip | < 1.17.0 | 1.17.0 |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade to FiftyOne 1.17.0 or later, which removes the hard-coded wildcard CORS header and defaults to same-origin-only responses (cross-origin access becomes explicit opt-in via
FIFTYONE_ALLOWED_ORIGINS, including a*escape hatch that logs a warning if truly needed). Until upgraded: never leave the FiftyOne App server running while browsing untrusted websites, keep it bound tolocalhost(the default — do not expose it on a network interface), and prefer a browser that enforces Private Network Access protections (Chromium 142+); Safari and Firefox do not yet block this. For detection, review FiftyOne server access logs for/mediarequests carrying unexpectedOriginheaders, and monitor ML workstation egress for connections to unfamiliar domains coincident with FiftyOne usage.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-53656?
FiftyOne, the popular open-source tool for visualizing and curating ML datasets, hard-codes a wildcard `Access-Control-Allow-Origin: *` header on its local, unauthenticated App/API server and its `/media` file-read endpoint, meaning any website a data scientist merely has open in the background can silently read files off their machine — no clicks required beyond the page load. With 2,957 downstream dependents and a package risk score of 32/100 reflecting 20 prior CVEs in the same codebase, this sits on a meaningful slice of ML engineering workstations, and the `/media?filepath=` parameter can pull SSH keys, cloud credentials, `.env` files, or proprietary dataset media straight through a browser's usual same-origin protections. There is no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template yet, so this is not a same-day fire drill, but the drive-by mechanics — Safari and Firefox still don't enforce Private Network Access protections against local servers — make it a live risk for anyone running FiftyOne locally while browsing normally. Upgrade to FiftyOne 1.17.0, which defaults to same-origin CORS and requires explicit opt-in via `FIFTYONE_ALLOWED_ORIGINS` for any cross-origin use; until then, don't run the App server while browsing untrusted sites and confirm it stays bound to localhost only.
Is CVE-2026-53656 actively exploited?
No confirmed active exploitation of CVE-2026-53656 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-53656?
Upgrade to FiftyOne 1.17.0 or later, which removes the hard-coded wildcard CORS header and defaults to same-origin-only responses (cross-origin access becomes explicit opt-in via `FIFTYONE_ALLOWED_ORIGINS`, including a `*` escape hatch that logs a warning if truly needed). Until upgraded: never leave the FiftyOne App server running while browsing untrusted websites, keep it bound to `localhost` (the default — do not expose it on a network interface), and prefer a browser that enforces Private Network Access protections (Chromium 142+); Safari and Firefox do not yet block this. For detection, review FiftyOne server access logs for `/media` requests carrying unexpected `Origin` headers, and monitor ML workstation egress for connections to unfamiliar domains coincident with FiftyOne usage.
What systems are affected by CVE-2026-53656?
This vulnerability affects the following AI/ML architecture patterns: training data pipelines, dataset curation/visualization tooling, local ML developer workstations, MLOps tooling.
What is the CVSS score for CVE-2026-53656?
CVE-2026-53656 has a CVSS v3.1 base score of 6.3 (MEDIUM). The EPSS exploitation probability is 0.12%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0025 Exfiltration via Cyber Means AML.T0037 Data from Local System AML.T0078 Drive-by Compromise Compliance Controls Affected
What are the technical details?
Original Advisory
FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/server/routes/media.py unconditionally return Access-Control-Allow-Origin: *. Because the embedded server is local and unauthenticated, a malicious website visited by the user can read cross-origin responses. The /media endpoint accepts a filesystem path, allowing a drive-by page to read files accessible to the server process and exfiltrate them without additional clicks. The allowed_origins configuration and FIFTYONE_ALLOWED_ORIGINS environment variable now make cross-origin access explicit, while the default policy is same-origin. This issue is fixed in version 1.17.0.
Exploitation Scenario
An attacker compromises an ad network, a niche technical forum, or sends a phishing link to an ML engineer who has FiftyOne's App server running locally (a common background state during dataset labeling sessions). The malicious page's JavaScript issues a background cross-origin request to `http://localhost:5151/media?filepath=/Users/victim/.ssh/id_rsa` (or `/etc/passwd`, a cloud `credentials` file, or a project `.env`). Because the server unconditionally sends `Access-Control-Allow-Origin: *`, the browser permits the malicious page's script to read the response body despite the origin mismatch. The script then relays the stolen file contents to an attacker-controlled endpoint via a second outbound request — the entire exfiltration completes silently while the victim continues browsing normally, with no visible indicator on either the malicious page or the FiftyOne UI.
Weaknesses (CWE)
CWE-346 Origin Validation Error
Primary
CWE-346 Origin Validation Error
Primary
CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
Primary
CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
Primary
CWE-346 Origin Validation Error CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains CWE-346 — Origin Validation Error: The product does not properly verify that the source of data or communication is valid.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N References
- github.com/advisories/GHSA-q78p-hj9h-5466
- github.com/voxel51/fiftyone/commit/7c5b92eec5c7c0210c0c8134351ced77d2800ae0
- github.com/voxel51/fiftyone/releases/tag/v1.17.0
- github.com/voxel51/fiftyone/security/advisories/GHSA-q78p-hj9h-5466
- github.com/voxel51/fiftyone/commit/6c4fa1b27bf53e4ba567742ffd20d033af7b9e64
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook