CVE 9.1 CRITICAL

Jellystat has SQL Injection that leads to to Remote Code Execution_CVE-2026-41167

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails` and `POST /api/getLibrary`, enabling full read of any table in the database - including `app_config`, which stores the Jellystat admin credentials, the Jellyfin API key, and the Jellyfin host URL. Because the vulnerable call site dispatches via `node-postgres`'s simple query protocol (no parameter array is passed), stacked queries are allowed, which escalates the injection from data disclosure to arbitrary command execution on the PostgreSQL host via `COPY ... TO PROGRAM`. Under the role shipped by the project's `docker-compose.yml` (a PostgreSQL superuser), no additional privileges are required to reach the RCE primitive. Version 1.1.10 contains a fix.

AI Analysis

SQL Injection vulnerability leading to Remote Code Execution

Basic Information

ID CVE-2026-41167
Source GitHub_M
Published Apr 22, 2026 at 20:39

Affected Product

Vendor CyferShepard
Product Jellystat
Version < 1.1.10
Affected Versions CyferShepard Jellystat < 1.1.10

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor CyferShepard
Product Jellystat
Version < 1.1.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.