CVE Explorer
CVE-2025-64178
Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the server, accepted a URL parameter that was directly passed to the cache package, which downloaded the poster from this URL. This URL parameter can be used to make the Jellysweep server download arbitrary content. The API endpoint can only be used by authenticated users. This issue is fixed in version 0.13.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"jellysweep","vendor":"jon4hz","versions":[{"status":"affected","version":"< 0.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a5a61558c2ef604dabb5caced7947b50fa212a2f0b668bdb161507c5c571af4f · sha256:8b7868f449cce8f8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.9,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a5a61558c2ef604dabb5caced7947b50fa212a2f0b668bdb161507c5c571af4f · sha256:8b7868f449cce8f8… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a5a61558c2ef604dabb5caced7947b50fa212a2f0b668bdb161507c5c571af4f · sha256:8b7868f449cce8f8… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/jon4hz/jellysweep/commit/17466312510966418aea941e4944229856d55101","tags":["x_refsource_MISC"],"url":"https://github.com/jon4hz/jellysweep/commit/17466312510966418aea941e4944229856d55101"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a5a61558c2ef604dabb5caced7947b50fa212a2f0b668bdb161507c5c571af4f · sha256:8b7868f449cce8f8… · /containers/cna/references/1
{"name":"https://github.com/jon4hz/jellysweep/security/advisories/GHSA-xc93-q32j-cpcg","tags":["x_refsource_CONFIRM"],"url":"https://github.com/jon4hz/jellysweep/security/advisories/GHSA-xc93-q32j-cpcg"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a5a61558c2ef604dabb5caced7947b50fa212a2f0b668bdb161507c5c571af4f · sha256:8b7868f449cce8f8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.