Path traversal in Jellyfin - CVE-2021-21402

 

Path traversal in Jellyfin - CVE-2021-21402

Published: March 22, 2021 / Updated: April 15, 2026


Vulnerability identifier: #VU126125
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21402
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose arbitrary files from the server file system.

The vulnerability exists due to path traversal in certain endpoints when handling specially crafted requests. A remote attacker can send specially crafted requests to disclose arbitrary files from the server file system.

The issue is more prevalent when Windows is used as the host operating system.


Affected software

Jellyfin

How to mitigate CVE-2021-21402

Install security update from vendor's website.

Jellyfin - update to 10.7.1

External References

Related Security Bulletins