VYPR
Critical severity9.0NVD Advisory· Published Nov 18, 2025· Updated Jun 17, 2026

CVE-2025-64325

CVE-2025-64325

Description

Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:emby:emby:*:*:*:*:*:*:*:*
    Range: <4.8.1.0
  • Emby/Emby Serverllm-fuzzy
    Range: <4.8.1.0, <4.9.0.0-beta
  • Emby/Securitycpe-rescue
    Range: Emby Server (Web App) < 4.8.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.