VulnerabilityAnalyzed
CVE-2025-32946
This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol.
MEDIUM 5.3EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-282
- Affected
- framasoft/peertube
- Source
- reefs@jfrog.com
References
- https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1Release Notes
- https://research.jfrog.com/vulnerabilities/peertube-arbitrary-playlist-creation-activitypub/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.