PT-2026-95549 · Kyoo · Kyoo

CVE-2026-77385

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kyoo versions prior to 5.1.0
Description A registered user with the core.play permission can provide a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleans the value and verifies it starts with Settings.SafePath before getHash() processes it. However, transcoder/src/api/streams.go serves the accepted path without verifying a catalog record. This lack of catalog-level authorization allows a user to retrieve hidden, temporary, operational, or other uncataloged files within the media directory if the path is known or guessed.
Recommendations Update to version 5.1.0.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77385
GHSA-FC8V-VR3Q-HC46

Affected Products

Kyoo