CVE-2025-64325: Emby Server is Vulnerable to Remote Code Execution Through XSS in Admin Dashboard
Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64325?
CVE-2025-64325 has been classified as a medium-severity vulnerability due to its potential for exploitation by a malicious user.
How do I fix CVE-2025-64325?
To fix CVE-2025-64325, update to Emby Server version 4.8.1.0 or later, or 4.9.0.0-beta or later.
What is the impact of CVE-2025-64325?
The impact of CVE-2025-64325 includes unauthorized device listings in the admin dashboard, potentially leading to further exploitation.
Who is affected by CVE-2025-64325?
Users of Emby Server versions prior to 4.8.1.0 and beta version 4.9.0.0 are affected by CVE-2025-64325.
What type of attack does CVE-2025-64325 involve?
CVE-2025-64325 involves an authentication attack where a malicious user sends a manipulated X-Emby-Client header.