← back
CVE-2025-32945

PeerTube Arbitrary Playlist Creation via REST API

CVSS 4.3 MEDIUMEPSS 0.3%CWE-282
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
15 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Chocobozzz/PeerTube

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →