PT-2026-52059 · Jellyfin+1 · Jellyfin+1

CVE-2026-48793

·

Published

2026-06-24

·

Updated

2026-06-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jellyfin versions prior to 10.11.10
Description An argument injection issue exists in the subtitle conversion process. The function ConvertTextSubtitleToSrtInternal() interpolates the subtitle file path into FFmpeg command-line arguments without proper normalization. On Linux systems, filenames containing double-quote characters can break argument quoting, allowing the injection of arbitrary FFmpeg arguments. This is reachable without authentication through the GetSubtitle endpoint of the SubtitleController. An attacker capable of placing a file in a media library directory, such as via a shared NAS or Samba share, could achieve arbitrary file write on the server and information disclosure.
Recommendations Update to version 10.11.10.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48793
GHSA-WWWM-PX48-FPVQ

Affected Products

Ffmpeg
Jellyfin