PatchSiren

seerr-team CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH seerr-team CVE published 2026-08-12

CVE-2026-73291

CVE-2026-73291 is a high-severity vulnerability in Seerr, a media request and discovery manager for Jellyfin, Plex, and Emby. The vulnerability exists in the ImageProxy component of Seerr, which allows an attacker to supply traversal sequences that can overwrite files outside the cache directory, potentially leading to code execution. This issue arises from the ImageProxy in server/lib/imageproxy.ts using [truncated]