{"id":"GHSA-xc93-q32j-cpcg","summary":"Jellysweep uses uncontrolled data in image cache API endpoint","details":"### Impact\nThe `/api/images/cache` which is used to download media posters from the server accepted an `url` parameter, which was directly passed to the cache package and that downloaded the poster from this URL.\nThis URL parameter can be used to make the jellysweep server download arbitrary content.\n\nThe API endpoint can only be used by authenticated users.\n\n### Patches\n\nFixed in `v0.13.0`. The affected (and now fixed) library was also moved to `internal/` because it wasn't meant to be imported.\n\n\n### References\nhttps://github.com/jon4hz/jellysweep/security/code-scanning/28","aliases":["CVE-2025-64178","GO-2025-4091"],"modified":"2025-11-17T19:42:42.415362Z","published":"2025-11-04T14:30:22Z","database_specific":{"github_reviewed_at":"2025-11-04T14:30:22Z","nvd_published_at":"2025-11-06T22:15:44Z","cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/jon4hz/jellysweep/security/advisories/GHSA-xc93-q32j-cpcg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64178"},{"type":"WEB","url":"https://github.com/jon4hz/jellysweep/commit/17466312510966418aea941e4944229856d55101"},{"type":"PACKAGE","url":"https://github.com/jon4hz/jellysweep"}],"affected":[{"package":{"name":"github.com/jon4hz/jellysweep","ecosystem":"Go","purl":"pkg:golang/github.com/jon4hz/jellysweep"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-xc93-q32j-cpcg/GHSA-xc93-q32j-cpcg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}]}