Description
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Recommendation
Update the jellyfin-web package to the latest compatible version. Followings are version details:
- Affected version(s): >= 10.8.0, < 10.8.4
- Patched version(s): 10.8.4
References
Related Issues
- Jellyfin Web Cross-Site Scripting (XSS) via Collection Name - CVE-2023-23635
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - CVE-2025-26619
- TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes - CVE-2023-48219
You might also like:
- Tags:
- npm
- jellyfin-web
Anything's wrong? Let us know Last updated on March 27, 2025


