Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins

Jellyfin has released version 12.0 of its media server, which includes several security patches and the removal of legacy client login support. The update also introduces stricter rules for plugin naming and improved parental controls to enhance server security.
Why it matters
These updates are critical for self-hosted media server administrators to prevent unauthorized access and mitigate potential vulnerabilities.
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the web interface.
On a misconfigured server, someone who had not signed in could get the setup wizard, the first-run pages that create the administrator account and point Jellyfin at your libraries, to run a second time.
Plugin packages with unsafe names are now rejected. Parental controls apply in places where they previously did not, and the web client has fixes for cross-site scripting, the bug class where content an attacker supplies runs as script inside another user’s browser session.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in