HIGH
seerr-team
CVE published 2026-08-12
CVE-2026-73291
CVE-2026-73291 is a high-severity vulnerability in Seerr, a media request and discovery manager for Jellyfin, Plex, and Emby. The vulnerability exists in the ImageProxy component of Seerr, which allows an attacker to supply traversal sequences that can overwrite files outside the cache directory, potentially leading to code execution. This issue arises from the ImageProxy in server/lib/imageproxy.ts using [truncated]