Jellyfin

Jellyfin

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 14.04.2026 22:31:44
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimit...

  • EPSS 0.12%
  • Veröffentlicht 14.04.2026 22:28:47
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOpti...

  • EPSS 0.04%
  • Veröffentlicht 14.04.2026 22:25:35
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths...

  • EPSS 0.24%
  • Veröffentlicht 14.04.2026 22:18:30
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the f...

  • EPSS 0.12%
  • Veröffentlicht 11.03.2026 17:16:58
  • Zuletzt bearbeitet 20.03.2026 16:39:05

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly al...

  • EPSS 0.71%
  • Veröffentlicht 15.04.2025 20:36:24
  • Zuletzt bearbeitet 06.10.2025 16:42:39

Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly achieve remote code execution by anyone with credentials to a low-privileged user. This vul...

  • EPSS 1.74%
  • Veröffentlicht 15.04.2025 20:08:52
  • Zuletzt bearbeitet 06.10.2025 16:49:44

Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the ability to restart their Jellyfin server. This endpoint is intended to be admins-only, but it also aut...

  • EPSS 0.17%
  • Veröffentlicht 02.09.2024 18:15:36
  • Zuletzt bearbeitet 21.11.2024 09:35:53

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack against an admin user via a specially crafted malicious SVG file. When viewed by an admin outside of the J...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 13.12.2023 21:15:07
  • Zuletzt bearbeitet 21.11.2024 08:32:17

Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file using `ProcessStartInfo` via the `ValidateVersion` function. A malicious administrator can setup a ne...

Exploit
  • EPSS 1.37%
  • Veröffentlicht 06.12.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:32:48

Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos/<itemId>/stream` and `/Videos/<itemId>/stream.<container>` endpoints whi...