
CVE-2025-61506 An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint. https://www.cve.org/CVERecord?id=CVE-2025-61506
Post summary
MediaCrush versions up to 1.0.1 allow remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint, exposing a remote file upload vulnerability.
