CVE 10 CRITICAL

Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain_CVE-2026-35031

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. This arbitrary file write can be chained into arbitrary file read via .strm files, database extraction, admin privilege escalation, and ultimately remote code execution as root via ld.so.preload. Exploitation requires an administrator account or a user that has been explicitly granted the "Upload Subtitles" permission. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can grant non-administrator users Subtitle upload permissions to reduce attack surface.

AI Analysis

Arbitrary file write and remote code execution via subtitle upload path traversal and .strm file chaining

Basic Information

ID CVE-2026-35031
Source GitHub_M
Published Apr 14, 2026 at 22:18

Affected Product

Vendor jellyfin
Product jellyfin
Version < 10.11.7
Affected Versions jellyfin jellyfin < 10.11.7

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Jellyfin
Product Jellyfin Media Server
Version < 10.11.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.