CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6636

As cited

Copy frozen at (site build).

vulnerabilities

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins

Jellyfin released version 12.0 with security fixes addressing path traversal vulnerabilities that could expose files outside designated directories, along with improvements to first-run setup, plugin installation, parental controls, and the web interface. The update also removes legacy client login methods and patches an issue where unauthenticated users could access the setup wizard on misconfigured instances.

Why it matters: Operators running Jellyfin media servers should update immediately to close path traversal and unauthenticated setup access vulnerabilities that could lead to data exposure or account compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary