CVE-2025-32945
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 15, 2025
CWE ID 282
Summary
CVE-2025-32945 is a vulnerability in PeerTube's REST API. It enables an existing user to create playlists for other users' channels, as the API incorrectly sets the playlist owner to the requester and the associated channel ID without verification. This issue could potentially lead to unauthorized content addition and misuse of other users' channels.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PeerTube