CVE-2025-51058: Vedo Suite Project Vedo Suite

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the "file" URL parameter.

Affected products

Published 2025-08-06. Last modified 2026-07-05.