Vulnerability record · CVE-2021-21402 · published 23 March 2021
CVE-2021-21402: Jellyfin path traversal allows arbitrary file read
Jellyfin · Jellyfin
Jellyfin before 10.7.1 fails to properly validate paths on certain endpoints, allowing crafted requests to read arbitrary files from the server filesystem. The flaw is a path traversal (CWE-22) and is more prevalent when Jellyfin runs on Windows. Internet-exposed servers are potentially at risk.
Description
Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the host OS. Servers that are exposed to the public Internet are potentially at risk. This is fixed in version 10.7.1. As a workaround, users may be able to restrict some access by enforcing strict security permissions on their filesystem, however, it is recommended to update as soon as possible.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw allows high-confidentiality file read with a trivial network vector and has very high EPSS, though it requires low privileges and a patch is available.
What it is
Jellyfin before 10.7.1 fails to properly validate paths on certain endpoints, allowing crafted requests to read arbitrary files from the server filesystem. The flaw is a path traversal (CWE-22) and is more prevalent when Jellyfin runs on Windows. Internet-exposed servers are potentially at risk.
Impact
An authenticated attacker can read files outside the intended media directories, exposing configuration, credentials or other sensitive data on the host. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.
Attack surface
Reachable over the network via HTTP requests to affected endpoints; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No public-internet exposure is required, but the advisory notes publicly exposed servers are at greater risk.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is very high (0.803 probability, 99.6th percentile), and references include a patch commit and release notes, indicating public technical detail is available.
What to do
- Upgrade Jellyfin to version 10.7.1 or later, which contains the fix.
- If immediate upgrade is not possible, enforce strict filesystem permissions to limit what the Jellyfin service account can read.
- Restrict network access to Jellyfin management and API endpoints; avoid exposing the server directly to the public internet.
- Run Jellyfin under a dedicated low-privilege account with access limited to media directories.
- Review logs and file access for signs of traversal attempts against affected endpoints.
Detection
- Monitor HTTP requests containing path traversal sequences (../, ..\, encoded variants) to Jellyfin endpoints.
- Alert on Jellyfin service account reads of files outside configured media or data directories.
- Audit for access to sensitive files such as configuration, credential or system files by the Jellyfin process.
- Correlate unusual file-read activity with requests from low-privileged or unexpected client accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/jellyfin/jellyfin/commit/0183ef8e89195f420c48d2600bc0b72f6d3a7fd7 | PatchThird Party Advisory |
| https://github.com/jellyfin/jellyfin/releases/tag/v10.7.1 | Release NotesThird Party Advisory |
| https://github.com/jellyfin/jellyfin/security/advisories/GHSA-wg4c-c9g9-rxhx | Third Party Advisory |
| https://github.com/jellyfin/jellyfin/commit/0183ef8e89195f420c48d2600bc0b72f6d3a7fd7 | PatchThird Party Advisory |
| https://github.com/jellyfin/jellyfin/releases/tag/v10.7.1 | Release NotesThird Party Advisory |
| https://github.com/jellyfin/jellyfin/security/advisories/GHSA-wg4c-c9g9-rxhx | Third Party Advisory |
Track CVE-2021-21402 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21402), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.