← Vulnerability feed

Vulnerability record · CVE-2021-21402 · published 23 March 2021

CVE-2021-21402: Jellyfin path traversal allows arbitrary file read

Jellyfin · Jellyfin

Jellyfin before 10.7.1 fails to properly validate paths on certain endpoints, allowing crafted requests to read arbitrary files from the server filesystem. The flaw is a path traversal (CWE-22) and is more prevalent when Jellyfin runs on Windows. Internet-exposed servers are potentially at risk.

6.5 CVSS 3.1 Medium EPSS 79% · top 0.4% CWE-22 · Path traversal
6.5CVSS 3.1 base score, v2 4.0
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the host OS. Servers that are exposed to the public Internet are potentially at risk. This is fixed in version 10.7.1. As a workaround, users may be able to restrict some access by enforcing strict security permissions on their filesystem, however, it is recommended to update as soon as possible.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows high-confidentiality file read with a trivial network vector and has very high EPSS, though it requires low privileges and a patch is available.

What it is

Jellyfin before 10.7.1 fails to properly validate paths on certain endpoints, allowing crafted requests to read arbitrary files from the server filesystem. The flaw is a path traversal (CWE-22) and is more prevalent when Jellyfin runs on Windows. Internet-exposed servers are potentially at risk.

Impact

An authenticated attacker can read files outside the intended media directories, exposing configuration, credentials or other sensitive data on the host. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.

Attack surface

Reachable over the network via HTTP requests to affected endpoints; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No public-internet exposure is required, but the advisory notes publicly exposed servers are at greater risk.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is very high (0.803 probability, 99.6th percentile), and references include a patch commit and release notes, indicating public technical detail is available.

What to do

  • Upgrade Jellyfin to version 10.7.1 or later, which contains the fix.
  • If immediate upgrade is not possible, enforce strict filesystem permissions to limit what the Jellyfin service account can read.
  • Restrict network access to Jellyfin management and API endpoints; avoid exposing the server directly to the public internet.
  • Run Jellyfin under a dedicated low-privilege account with access limited to media directories.
  • Review logs and file access for signs of traversal attempts against affected endpoints.

Detection

  • Monitor HTTP requests containing path traversal sequences (../, ..\, encoded variants) to Jellyfin endpoints.
  • Alert on Jellyfin service account reads of files outside configured media or data directories.
  • Audit for access to sensitive files such as configuration, credential or system files by the Jellyfin process.
  • Correlate unusual file-read activity with requests from low-privileged or unexpected client accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21402 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31852Jellyfin improper privilege management vulnerabilityJellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut…EPSS 0.62%9.3CVE-2026-35033Jellyfin argument injection vulnerabilityJellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…EPSS 0.52%8.8CVE-2026-35031Jellyfin improper input validation vulnerabilityJellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V…EPSS 0.92%8.8CVE-2023-49096Jellyfin argument injection vulnerabilityJellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosControlle…EPSS 1.3%8.8CVE-2022-35909Jellyfin vulnerabilityIn Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.EPSS 1.6%8.6CVE-2026-35032Jellyfin server-side request forgery (ssrf) vulnerabilityJellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /…EPSS 0.38%8.1CVE-2023-30626Jellyfin path traversal vulnerabilityJellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid…EPSS 2.0%7.6CVE-2025-31499Jellyfin argument injection vulnerabilityJellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to…EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2021-21402), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.