CVE-2025-55795

Source
https://cve.org/CVERecord?id=CVE-2025-55795
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55795.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55795
Aliases
  • GHSA-87c5-mc8v-xf7r
Published
2025-09-29T00:00:00Z
Modified
2026-08-12T03:51:15.494113796Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a higher user ID without proper verification. This results in the victim's email being reassigned to the attacker's account, causing the victim to be locked out immediately and unable to log in. The vulnerability leads to denial of service via account lockout but does not grant the attacker direct access to the victim's private data.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55795.json"
}
References

Affected packages

Git / github.com/openml/openml.org

Affected ranges

Type
GIT
Repo
https://github.com/openml/openml.org
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:openml:openml.org:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.20241110"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v2.*
v2.0.20241110

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55795.json"