PT-2025-45793 · Go · Github.Com/Jon4Hz/Jellysweep

Published

2025-11-04

·

Updated

2025-11-04

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Impact

The /api/images/cache which is used to download media posters from the server accepted an url parameter, which was directly passed to the cache package and that downloaded the poster from this URL. This URL parameter can be used to make the jellysweep server download arbitrary content.
The API endpoint can only be used by authenticated users.

Patches

Fixed in v0.13.0. The affected (and now fixed) library was also moved to internal/ because it wasn't meant to be imported.

References

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-XC93-Q32J-CPCG

Affected Products

Github.Com/Jon4Hz/Jellysweep