Intel

AIKIDO-2025-10650

mage-ai is vulnerable to Initialization of a Resource with an Insecure Default

Initialization of a Resource with an Insecure DefaultCVE-2025-2129

61

Medium Risk

This Affects:

PYTHONmage-ai
0.7.90 - 0.9.77
Fixed in 0.9.78

TL;DR

Affected versions of this package ship with an insecure default for the REQUIRE_USER_AUTHENTICATION setting. An attacker can initiate this remotely; while exploitation is reported to be non-trivial (higher complexity) and considered difficult in practice, a public disclosure exists and may enable real-world abuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mage-ai is vulnerable to Initialization of a Resource with an Insecure Default in versions 0.7.90 - 0.9.77.

How to fix this

Upgrade the mage-ai library to the patch version or set REQUIRE_USER_AUTHENTICATION to true.