PT-2026-95549 · Kyoo · Kyoo
CVE-2026-77385
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kyoo versions prior to 5.1.0
Description
A registered user with the
core.play permission can provide a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleans the value and verifies it starts with Settings.SafePath before getHash() processes it. However, transcoder/src/api/streams.go serves the accepted path without verifying a catalog record. This lack of catalog-level authorization allows a user to retrieve hidden, temporary, operational, or other uncataloged files within the media directory if the path is known or guessed.Recommendations
Update to version 5.1.0.
Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kyoo