Unauthorized Access Vulnerability in Kyoo Media Server
CVE-2026-77385
4.3MEDIUM
What is CVE-2026-77385?
Kyoo, a self-hosted media server designed for managing movies, series, and anime, is susceptible to an unauthorized access vulnerability. This issue arises when registered users with the core.play permission can provide a base64-encoded filesystem path to the transcoder. The path validation process only ensures the path begins with Settings.SafePath, neglecting to verify a corresponding Kyoo catalog record. Consequently, users can access hidden, temporary, or non-cataloged files within the media directory if they know or can guess the path. This vulnerability was resolved in version 5.1.0.
Affected Version(s)
Kyoo < 5.1.0
