Description
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Recommendation
Update the jellyfin-web package to the latest compatible version. Followings are version details:
- Affected version(s): >= 10.8.0, < 10.8.4
- Patched version(s): 10.8.4
References
Could your website be exposed too?
SmartScanner can check your website for Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Jellyfin Web Cross-Site Scripting (XSS) via Collection Name - CVE-2023-23635
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - CVE-2025-26619
- TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes - CVE-2023-48219
You might also like:
See something that needs correcting? Let us knowUpdated March 27, 2025


