CVE-2025-64115

Source
https://cve.org/CVERecord?id=CVE-2025-64115
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64115.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64115
Aliases
  • GHSA-pm58-79jw-q79f
Published
2025-10-30T17:39:19.330Z
Modified
2026-04-02T12:59:14.050320Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Movary unvalidated Referer header allows open redirect and phishing
Details

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in multiple settings endpoints, allowing a crafted link to cause an open redirect to an attacker-controlled site and facilitate phishing. This vulnerability is fixed in 0.69.0.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64115.json"
}
References

Affected packages

Git / github.com/leepeuker/movary

Affected ranges

Type
GIT
Repo
https://github.com/leepeuker/movary
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.17.0
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.19.3
0.19.4
0.2.0
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.25.4
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.3.0
0.30.0
0.31.0
0.31.1
0.32.0
0.32.1
0.32.2
0.33.0
0.33.1
0.33.2
0.33.3
0.34.0
0.35.0
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.35.7
0.35.8
0.36.0
0.37.0
0.38.0
0.38.1
0.39.0
0.39.1
0.39.2
0.39.3
0.39.4
0.4.0
0.4.1
0.4.2
0.40.0
0.41.0
0.42.0
0.43.0
0.44.0
0.45.0
0.46.0
0.46.1
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5.0
0.50.0
0.51.0
0.52.0
0.53.0
0.53.1
0.54.0
0.55.0
0.55.1
0.56.0
0.57.0
0.58.0
0.59.0
0.6.0
0.60.0
0.61.0
0.62.0
0.62.1
0.62.2
0.63.0
0.64.0
0.64.1
0.65.0
0.66.0
0.66.1
0.66.2
0.67.0
0.68.0
0.7.0
0.8.0
0.9.0
0.9.1
0.9.2
0.9.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64115.json"