Description
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Recommendation
Update the jellyfin-web package to the latest compatible version. Followings are version details:
- Affected version(s): >= 10.8.0, < 10.8.4
- Patched version(s): 10.8.4
References
Could your website be exposed too?
SmartScanner can check your website for Jellyfin Web Cross-Site Scripting (XSS) via Collection Name and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name - CVE-2023-23636
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- @mattkrick/sanitize-svg vulnerable to Cross-Site Scripting (XSS) - CVE-2023-22461
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - vega - CVE-2025-26619
You might also like:
See something that needs correcting? Let us knowUpdated March 27, 2025


