PT-2025-43786 · Gerrit Van Aaken · Podlove Web Player

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-62908

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Missing Authorization vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Podlove Web Player: from n/a through <= 5.9.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-62908

Affected Products

Podlove Web Player