Server-Side Request Forgery Vulnerability in Specific Product by Vendor
CVE-2025-46385

8.6HIGH

Key Information:

Vendor

Emby

Status
Vendor
CVE Published:
20 July 2025

What is CVE-2025-46385?

A Server-Side Request Forgery (SSRF) vulnerability allows an attacker to send crafted requests from the server to internal resources, potentially exposing sensitive information or enabling further exploits. This vulnerability can lead to unauthorized access to backend systems and services, posing significant security risks for the affected product.

Affected Version(s)

Windows 4.8

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guy Hayou
.
CVE-2025-46385 : Server-Side Request Forgery Vulnerability in Specific Product by Vendor