Jellyfin versions prior to 10.11.7 contain a critical vulnerability in the subtitle upload endpoint that allows authenticated users with administrator privileges or explicit subtitle upload permissions to perform arbitrary file writes through insufficient validation of the Format field. This vulnerability can be exploited to achieve remote code execution with root privileges by chaining the file write capability into arbitrary file read operations, database extraction, and privilege escalation through ld.so.preload manipulation. The vulnerability has a CVSS score of 9.9 (Critical) with a network attack vector, low complexity, and requirements for low privilege access. The exploit chain results in complete compromise of confidentiality, integrity, and availability across the affected system. The EPSS score of 0.002840000 indicates relatively low prevalence among known vulnerabilities, though the high CVSS score reflects significant potential impact. There is no evidence of active exploitation in the wild, and the vulnerability does not appear on CISA's Known Exploited Vulnerabilities list. The patch is available in version 10.11.7 and was released following responsible disclosure. Organizations unable to immediately upgrade should consider restricting subtitle upload permissions to administrative accounts only to minimize attack surface.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.11.7CPE matchmatch criteria | cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.