Jellyfin 12.0 Fixes Security Flaws Allowing Unauthorized File Access and XSS
Brief
Jellyfin has released version 12.0, introducing multiple security fixes that address unauthorized file-access risks, cross-site scripting (XSS) weaknesses, insecure plugin package handling, and setup-wizard exposure on misconfigured servers.
The major open-source media-server update, published September 7, 2026, also delivers extensive database migrations, performance improvements, book and comic support, API changes, and a new default Modern web layout.
The release fixes several flaws that could allow crafted requests to access files outside the directories Jellyfin is intended to expose.
Jellyfin 12.0 Fixes Security Flaws
Path traversal-style weaknesses are particularly serious for self-hosted media platforms because a successful exploit could expose configuration data, application files, credentials, or unrelated files stored on the underlying host.
