Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.

Subscriptions

Vendors Products

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 15 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:emby:emby:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Fri, 21 Nov 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Emby
Emby emby
Vendors & Products Emby
Emby emby

Wed, 19 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 22:45:00 +0000

Type Values Removed Values Added
Description Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.
Title Emby Server is Vulnerable to Remote Code Execution Through XSS in Admin Dashboard
Weaknesses CWE-116
CWE-79
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-19T16:44:25.026Z

Reserved: 2025-10-30T17:40:52.028Z

Link: CVE-2025-64325

cve-icon Vulnrichment

Updated: 2025-11-19T16:44:07.625Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-18T23:15:55.497

Modified: 2026-01-15T22:01:52.010

Link: CVE-2025-64325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-21T09:16:04Z

Weaknesses