Executive brief
Jellyfin is an open-source media server used to organize and stream movies, shows, and music. A security flaw in how the server handles subtitle files allows an attacker to inject malicious commands into the media processing engine. If an attacker can place a specially named file in a media folder (such as through a shared network drive or guest upload), they could potentially steal sensitive data or write unauthorized files to the server.
Technical details
An argument injection vulnerability exists in Jellyfin's subtitle conversion logic within SubtitleEncoder.ConvertTextSubtitleToSrtInternal. The application interpolates subtitle file paths into FFmpeg command-line arguments without proper normalization via EncodingUtils.NormalizePath(). On Linux systems, an attacker can use double-quote characters in filenames to break out of the intended argument quoting and inject arbitrary FFmpeg parameters. While the SubtitleController.GetSubtitle endpoint is reachable without authentication, the exploit requires the precondition of placing a malicious file into a directory scanned by the media library (e.g., via SMB, NFS, or guest uploads). Successful exploitation can lead to arbitrary file writes or information disclosure. The issue is resolved in version 10.11.10.
Affected products
- Jellyfin Jellyfin < 10.11.10
Timeline
- 2026-06-10: advisory: GitHub Security Advisory published
- 2026-06-24: disclosed: NVD publication date