Junglewise Threat Intelligence

CVE-2026-35033: Jellyfin ffmpeg argument injection arbitrary file read in StreamOptions

CVE-2026-35033 · Severity: critical · CVSS 9.1 · Published 2026-04-14

Technologies: Jellyfin. Vendors: Jellyfin.

Executive brief

Jellyfin is an open-source media server used to host and stream personal video and audio collections. A security flaw allows unauthorized users to trick the server into reading sensitive system files (such as passwords or configuration data) and displaying their contents inside a video stream. This could lead to a full system compromise or the theft of sensitive administrative data.

Technical details

An argument injection vulnerability exists in Jellyfin's `ParseStreamOptions` method within `StreamingHelpers.cs`. The application fails to validate lowercase query parameters, allowing an attacker to bypass regex filters and inject arbitrary arguments into the ffmpeg command line. Specifically, by manipulating the `h264-level` parameter, an attacker can inject a `drawtext` filter with a `textfile` argument to read files like `/etc/shadow`. While the `/Videos/{itemId}/stream` endpoint lacks an authorization attribute, an attacker must still know or obtain a pseudorandom item GUID to successfully trigger the exploit. The issue is resolved in version 10.11.7 by improving input sanitization.

Affected products

  • Jellyfin Jellyfin < 10.11.7

Timeline

  • 2023-03-31: patched: Version 10.11.7 released
  • 2026-04-14: advisory: Security advisory and CVE published

References

Related threats