CVE-2025-34452 - CVE House
Back to Database
Status published High CVE-2025-34452

Streama Subtitle Download Path Traversal and SSRF Leading to Arbitrary File Write

Vulnerability Description

Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-side request forgery (SSRF) vulnerabilities in that allow an authenticated attacker to write arbitrary files to the server filesystem. The issue exists in the subtitle download functionality, where user-controlled parameters are used to fetch remote content and construct file paths without proper validation. By supplying a crafted subtitle download URL and a path traversal sequence in the file name, an attacker can write files to arbitrary locations on the server, potentially leading to remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34452

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Valentin Lobstein (Chocapikk)

Affected Vendor

Affected Software

Streama
Vulnerable Versions:
1.10.0, b7c8767d25634e159f9e8844230465f29c16efc8

Timeline

Official Publish: December 18th, 2025
Last Modified: July 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)