VYPR
Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Nov 19, 2025

Emby Server is Vulnerable to Remote Code Execution Through XSS in Admin Dashboard

CVE-2025-64325

Description

Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.

Affected products

2
  • Emby/Emby Serverllm-fuzzy
    Range: <4.8.1.0, <4.9.0.0-beta
  • EmbySupport/Emby.Securityv5
    Range: Emby Server (Web App) < 4.8.1.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.