Jellyfin versions prior to 10.11.7 contain a critical vulnerability chain in the LiveTV M3U tuner endpoint that fails to validate tuner URLs, permitting local file read operations and server-side request forgery attacks. The flaw is particularly dangerous because the EnableLiveTvManagement permission defaults to true for all new users, making it exploitable by any authenticated user without requiring special privileges. An attacker can weaponize this by adding a malicious M3U tuner that exfiltrates the Jellyfin database, extract admin session tokens, and escalate to administrator access. The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) with a network attack vector, low complexity, and requires only low privileges and user interaction. The attack has high confidentiality and integrity impacts, as attackers can both read sensitive files including database contents and potentially modify system configuration. The EPSS score of 0.0004 indicates minimal current exploitation activity in the wild, though the moderate FAUCET Risk Score of 49.0 suggests notable community concern. This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog, nor is it on the Hot List for active exploitation. No publicly available exploit code has emerged based on available intelligence. Remediation through upgrade to version 10.11.7 is strongly recommended, with the alternative mitigation of disabling Live TV Management privileges for all users available for organizations unable to patch immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.11.7CPE matchmatch criteria | cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.