Unrated severityOSV Advisory· Published Apr 15, 2025· Updated Apr 15, 2025
PeerTube ActivityPub Playlist Creation Blind SSRF and DoS
CVE-2025-32948
Description
The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.
Affected products
1- Range: v0.0.11-alpha, v0.0.12-alpha, v0.0.13-alpha, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1mitrepatch
- research.jfrog.com/vulnerabilities/peertube-activitypub-playlist-creation-blind-ssrf-dos/mitrethird-party-advisory
News mentions
0No linked articles in our index yet.