Intel

AIKIDO-2025-10239

inference is vulnerable to Improper Authorization

Improper AuthorizationCVE-2025-29927 Published Apr 15, 2025

79

High Risk

This Affects:

PYTHONinference
0.7.0 - 0.43.0
Fixed in 0.44.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Next.js's CVE-2025-29927, where the inference server landing page built with Next.js allows bypassing of authorization checks when those checks are implemented in middleware. This issue has been patched to prevent unauthorized access within Next.js applications.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

inference is vulnerable to Improper Authorization in versions 0.7.0 - 0.43.0.

How to fix this

Upgrade the inference library to the patch version.