Cross-Site Scripting Vulnerability in Komga Media Server
CVE-2025-52880

4.2MEDIUM

Key Information:

Vendor

Gotson

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-52880?

A Cross-Site Scripting (XSS) vulnerability has been identified in the Komga media server, versions 1.8.0 through 1.21.3, which affects the handling of EPUB resources. Attackers can exploit this vulnerability by uploading a malicious EPUB file to a Komga library and prompting an admin user to access it via the EPUB reader. This could facilitate actions being executed on behalf of the admin, potentially allowing the attacker to gain control over server-side commands and execute arbitrary code. Version 1.22.0 resolves this security issue.

Affected Version(s)

komga >= 1.8.0, < 1.22.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52880 : Cross-Site Scripting Vulnerability in Komga Media Server