Junglewise Threat Intelligence

CVE-2026-49246: Jellyfin path traversal in MKV attachment extraction

CVE-2026-49246 · Severity: info · CVSS 1.7 · Published 2026-06-24

Technologies: Jellyfin. Vendors: Jellyfin.

Executive brief

Jellyfin is an open-source media server used to organize and stream personal media collections. A vulnerability exists where a specially crafted video file (MKV) can trick the server into writing files to unintended locations on the host system when the video is played. This could potentially allow an attacker to overwrite system files or disrupt operations if a user adds and plays a malicious video file from an untrusted source.

Technical details

A path traversal vulnerability exists in Jellyfin's MKV attachment extraction logic within PathManager.GetAttachmentPath. The application treats the filename tag within MKV attachments as trusted, passing it unsanitized to .NET's Path.Combine method. Because Path.Combine does not normalize '..' sequences or reject rooted second arguments, a malicious MKV file can redirect file extraction to arbitrary absolute paths on the host disk. The exploit is triggered automatically when a client attempts to play the video, as the server tries to extract attachments (such as subtitles). This issue is resolved in version 10.11.10.

Affected products

  • Jellyfin Jellyfin < 10.11.10

Timeline

  • 2026-06-10: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats