CVE-2025-55795 Details
Description
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a higher user ID without proper verification. This results in the victim's email being reassigned to the attacker's account, causing the victim to be locked out immediately and unable to log in. The vulnerability leads to denial of service via account lockout but does not grant the attacker direct access to the victim's private data.
A denial-of-service vulnerability has been identified in the OpenML web application, specifically in version 2.0.20241110 and prior. The issue arises from the use of incremental user IDs and inadequate email ownership verification during email update processes. An authenticated attacker with a lower user ID can change their email address to that of another user with a higher user ID, without proper verification. This action transfers the victim's email to the attacker's account, immediately locking the victim out of their account and disrupting their access. While the vulnerability does not provide direct access to the victim's private data, it causes significant disruption by invalidating the victim's access token and hijacking their email address.
Users are advised to update to a version of OpenML later than 2.0.20241110, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openml | [email protected] | Product |
| https://github.com/openml/openml.org | [email protected] | Product |
| https://github.com/openml/openml.org/security/advisories/GHSA-87c5-mc8v-xf7r | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
| CWE-639 | Authorization Bypass Through User-Controlled Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| openml openml.org | <= 2.0.20241110 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | Initial Analysis | [email protected] |
| Sep 29, 2025 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | New CVE Received | [email protected] |