CVE-2023-23636: Jellyfin

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.

Affected products

  • Jellyfin Jellyfin: from 10.8.0, up to and including 10.8.3

Published 2023-02-03. Last modified 2026-06-17.