PT-2026-109318 · Wizarrrr · Wizarr
CVE-2026-108264
·
Publicado
2026-10-09
·
Atualizado
2026-10-09
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator importing an untrusted bundle through POST /settings/wizard/import, could execute arbitrary Python when GET /wizard/{server}/{idx} rendered the stored step; app/jinja filters.py and app/services/wizard widgets.py contained additional evaluation sinks. This could execute operating-system commands as the application user, disclose the Flask SECRET KEY, access connected service credentials and the database, and produce stored cross-site scripting. This issue is fixed in 2026.9.1.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wizarr