PT-2026-71114 · Seerr · Seerr

CVE-2026-73291

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

7.1

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Seerr versions prior to 3.4.0
Description The ImageProxy component in server/lib/imageproxy.ts uses upstream ETag and Content-Type response headers to create cache filenames for the unauthenticated GET '/avatarproxy/:jellyfinUserId' endpoint. A malicious or compromised media server, or a man-in-the-middle attacker on a plaintext connection, can provide traversal sequences. These sequences are normalized by path.join() and fs.writeFile() outside the cache directory, enabling the overwriting of /app/dist/index.js or other critical files. This can lead to remote code execution as the node user following a container restart.
Recommendations Update to version 3.4.0.

Exploit

Fix

RCE

Code Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73291
GHSA-MC6W-69R3-62H8

Affected Products

Seerr