Arbitrary Code Execution Vulnerability in Wizarr for Jellyfin and Plex
CVE-2026-108264
What is CVE-2026-108264?
Wizarr, an advanced user invitation and management system for media servers like Jellyfin and Plex, was found to have a serious vulnerability prior to version 2026.9.1. In this version, user-supplied Markdown content underwent evaluation in a non-sandboxed environment which exposed application globals. This flaw allowed authenticated users, including administrators importing untrusted bundles, to execute arbitrary Python code during the rendering of stored steps. This could lead to unauthorized operating system command execution, potential exposure of sensitive information like the Flask SECRET_KEY, access to service credentials, database leakage, and the possibility of stored cross-site scripting. Effective security measures have been implemented in version 2026.9.1 to mitigate this risk.
Affected Version(s)
wizarr < 2026.9.1
