Executive brief
Jellyfin is an open-source media server used to host and stream personal video and audio collections. A security flaw allows unauthorized users to trick the server into reading sensitive system files (such as passwords or configuration data) and displaying their contents inside a video stream. This could lead to a full system compromise or the theft of sensitive administrative data.
Technical details
An argument injection vulnerability exists in Jellyfin's `ParseStreamOptions` method within `StreamingHelpers.cs`. The application fails to validate lowercase query parameters, allowing an attacker to bypass regex filters and inject arbitrary arguments into the ffmpeg command line. Specifically, by manipulating the `h264-level` parameter, an attacker can inject a `drawtext` filter with a `textfile` argument to read files like `/etc/shadow`. While the `/Videos/{itemId}/stream` endpoint lacks an authorization attribute, an attacker must still know or obtain a pseudorandom item GUID to successfully trigger the exploit. The issue is resolved in version 10.11.7 by improving input sanitization.
Affected products
- Jellyfin Jellyfin < 10.11.7
Timeline
- 2023-03-31: patched: Version 10.11.7 released
- 2026-04-14: advisory: Security advisory and CVE published