#VU126126 Improper Neutralization of Argument Delimiters in a Command in Jellyfin - CVE-2026-35033
Published: April 15, 2026
Jellyfin
Jellyfin
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of argument delimiters in a command in the ParseStreamOptions method in StreamingHelpers.cs and the /Videos/{itemId}/stream endpoint when processing StreamOptions query parameters. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue can be exploited without authentication, and injected ffmpeg arguments can cause server file contents to be rendered into the video stream response.