CVE-2025-32946
This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be the user who performed the request, and then sets the associated channel to the channel ID supplied by the request, without checking if it belongs to the user.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-282
- Published
- 2025-04-15
- Last modified
- 2026-03-13
Weakness type
Related vulnerabilities
- CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
- CVE-2026-50130 — Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
- CVE-2026-40214 — In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project...
- CVE-2026-3867 — An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because...
- CVE-2026-23514 — Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
- CVE-2025-57732 — In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory...
- CVE-2025-1112 — IBM OpenPages with Watson information disclosure
- CVE-2025-46416 — The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can...