Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the server, accepted a URL parameter that was directly passed to the cache package, which downloaded the poster from this URL. This URL parameter can be used to make the Jellysweep server download arbitrary content. The API endpoint can only be used by authenticated users. This issue is fixed in version 0.13.0.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jellysweep Project
Jellysweep Project jellysweep |
|
| Vendors & Products |
Jellysweep Project
Jellysweep Project jellysweep |
Thu, 06 Nov 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to download media posters from the server, accepted a URL parameter that was directly passed to the cache package, which downloaded the poster from this URL. This URL parameter can be used to make the Jellysweep server download arbitrary content. The API endpoint can only be used by authenticated users. This issue is fixed in version 0.13.0. | |
| Title | Jellysweep uses uncontrolled data in image cache API endpoint | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-06T21:46:58.994Z
Updated: 2025-11-07T14:59:57.782Z
Reserved: 2025-10-28T21:07:16.439Z
Link: CVE-2025-64178
Updated: 2025-11-07T14:59:54.677Z
Status : Received
Published: 2025-11-06T22:15:44.193
Modified: 2025-11-06T22:15:44.193
Link: CVE-2025-64178
No data.