CVE-2025-13803
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.
Published 2025-12-01. Last modified 2026-09-03.