CVE-2025-24960

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Feb 3, 2025
CWE ID 22

Summary

CVE-2025-24960 is a path traversal vulnerability affecting the Jellystat app for Jellyfin. In vulnerable versions, user input is utilized directly in the app's routes, increasing the risk of path traversal attacks. This issue primarily affects admin users, who can delete any file through the `DELETE files/:filename` endpoint. Although the impact is limited due to user access restrictions, it is recommended that users upgrade to version 1.1.3 to mitigate this risk. Unfortunately, there are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share