
Jellyfin 12.0 Fixes Security Flaws Allowing Unauthorized File Access and XSS
Jellyfin has released version 12.0, introducing multiple security fixes that address unauthorized file-access risks, cross-site scripting (XSS) weaknesses, insecure plugin package handling, and setup-wizard exposure on misconfigured servers. The major open-source media-server update, published September 7, 2026, also delivers extensive database migrations, performance improvements, book and comic support, API changes, and a new default Modern […]
The post Jellyfin 12.0 Fixes Security Flaws Allowing Unauthorized File Access and XSS appeared first on Cyber Security News.