CVE-2026-40086 | danielgatis rembg up to 2.0.74 model_path path traversal (GHSA-3wqj-33cg-xc48)
A vulnerability, which was classified as critical, has been found in danielgatis rembg up to 2.0.74. Affected is an unknown function. The manipulation of the argument model_path leads to path traversal.
This vulnerability is documented as CVE-2026-40086. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.