No CVSS.
treama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the server filesystem. The issue exists in the subtitle download functionality, where user-controlled parameters are used to fetch remote content and construct file paths without proper validation. By supplying a crafted subtitle download URL and a path traversal sequence in the file name, an attacker can write files to arbitrary locations on the server, potentially leading to remote code execution.
No configuration.
19 Dec 2025, 18:00
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-12-18 22:15
Updated : 2025-12-19 18:00
NVD link : CVE-2025-34452
Mitre link : CVE-2025-34452
CVE.ORG link : CVE-2025-34452
JSON object : View
No product.