CVE-2025-64178
Last modified
CVE-2025-64178 is a high-severity vulnerability rated 8.9/10 on the CVSS scale. Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the server, accepted a URL parameter that was directly passed to the cache package, which downloaded the poster from this URL. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the server, accepted a URL parameter that was directly passed to the cache package, which downloaded the poster from this URL. This URL parameter can be used to make the Jellysweep server download arbitrary content. The API endpoint can only be used by authenticated users. This issue is fixed in version 0.13.0.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-64178?
How severe is CVE-2025-64178?
How do I fix CVE-2025-64178?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64171MARIN3R is a lightweight, CRD based envoy control plane for …8.7
- CVE-2025-64173Apollo Router Core is a configurable graph router written in…7.5
- CVE-2025-64174Magento-lts is a long-term support alternative to Magento Co…4.8
- CVE-2025-64175Gogs is an open source self-hosted Git service. In version 0…8.8
- CVE-2025-64176ThinkDashboard is a self-hosted bookmark dashboard built wit…6.1
- CVE-2025-64177ThinkDashboard is a self-hosted bookmark dashboard built wit…6.1
- CVE-2025-64179lakeFS is an open-source tool that transforms object storage…5.3
- CVE-2025-6418A vulnerability was found in code-projects Simple Online Hot…9.8
- CVE-2025-64180Manager-io/Manager is accounting software. In Manager Deskto…10
- CVE-2025-64181OpenEXR provides the specification and reference implementat…7.5
- CVE-2025-64182OpenEXR provides the specification and reference implementat…7.8
- CVE-2025-64183OpenEXR provides the specification and reference implementat…7.5
Are you affected by CVE-2025-64178?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
