Emby Server before 4.5.0 allows server-side request forgery (SSRF) via the Items/RemoteSearch/Image ImageURL parameter.
View the template here CVE-2020-26948.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-26948.yaml
References: