You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP URLs. This is exploitable by any authenticated user because the EnableLiveTvManagement permission defaults to true for all new users. An attacker can chain these vulnerabilities by adding an M3U tuner pointing to an attacker-controlled server, serving a crafted M3U with a channel pointing to the Jellyfin database, exfiltrating the database to extract admin session tokens, and escalating to admin privileges. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can disable Live TV Management privileges for all users.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Jellyfin, Description: Jellyfin es un servidor multimedia de código abierto autoalojado. Las versiones anteriores a la 10.11.7 contienen una cadena de vulnerabilidades en el punto final del sintonizador M3U de LiveTV (POST /LiveTv/TunerHosts), donde la URL del sintonizador no se valida, permitiendo la lectura de archivos locales a través de rutas que no son HTTP y la falsificación de petición del lado del servidor (SSRF) a través de URL HTTP. Esto es explotable por cualquier usuario autenticado porque el permiso EnableLiveTvManagement se establece en verdadero por defecto para todos los usuarios nuevos. Un atacante puede encadenar estas vulnerabilidades añadiendo un sintonizador M3U que apunte a un servidor controlado por el atacante, sirviendo un M3U manipulado con un canal que apunte a la base de datos de Jellyfin, exfiltrando la base de datos para extraer tokens de sesión de administrador y escalando a privilegios de administrador. Este problema ha sido solucionado en la versión 10.11.7. Si los usuarios no pueden actualizar inmediatamente, pueden deshabilitar los privilegios de gestión de Live TV para todos los usuarios.
New CVE Received from GitHub, Inc.4/14/2026 7:16:28 PM
Action
Type
Old Value
New Value
Added
Description
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP URLs. This is exploitable by any authenticated user because the EnableLiveTvManagement permission defaults to true for all new users. An attacker can chain these vulnerabilities by adding an M3U tuner pointing to an attacker-controlled server, serving a crafted M3U with a channel pointing to the Jellyfin database, exfiltrating the database to extract admin session tokens, and escalating to admin privileges. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can disable Live TV Management privileges for all users.