9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails` and `POST /api/getLibrary`, enabling full read of any table in the database - including `app_config`, which stores the Jellystat admin credentials, the Jellyfin API key, and the Jellyfin host URL. Because the vulnerable call site dispatches via `node-postgres`'s simple query protocol (no parameter array is passed), stacked queries are allowed, which escalates the injection from data disclosure to arbitrary command execution on the PostgreSQL host via `COPY ... TO PROGRAM`. Under the role shipped by the project's `docker-compose.yml` (a PostgreSQL superuser), no additional privileges are required to reach the RCE primitive. Version 1.1.10 contains a fix.
AI Analysis
SQL Injection vulnerability leading to Remote Code Execution
Basic Information
ID
CVE-2026-41167
Source
GitHub_M
Published
Apr 22, 2026 at 20:39
Affected Product
Vendor
CyferShepard
Product
Jellystat
Version
< 1.1.10
Affected Versions
CyferShepard Jellystat < 1.1.10
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
CyferShepard
Product
Jellystat
Version
< 1.1.10