Impact
A missing catalog‑level authorization check in Kyoo’s transcoder allows a registered user with core.play permission to supply a base64‑encoded file system path. The transcoder normalises the path only to confirm it begins with the configured SafePath, but the downstream file‑serving logic does not verify that the requested file is part of the catalog. This enables the user to read any file within the media directory when the path is known or can be guessed. The consequence is the unauthorized disclosure of hidden, temporary, or operational files, reflecting weaknesses in CWE‑639 (Authorization Bypass through Privileged Credentials) and CWE‑862 (Missing Authorization).
Affected Systems
All Kyoo installations running a version earlier than 5.1.0 are affected, as the flaw sits in the core transcoder logic and is not gated by environmental configuration. The impact applies to any environment where the application runs and the media directory is accessible to the process, provided a user has the core.play permission.
Risk and Exploitability
The CVSS base score of 4.3 reflects a low overall risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a legitimate user account with core.play permission; the user can invoke the transcoder endpoint with a base64‑encoded path, bypassing catalog checks and retrieving arbitrary files beneath the media directory. Because the user role is restricted, exploitation depends on an attacker’s ability to obtain such credentials or compromise an existing account. The vulnerability does not grant remote code execution or denial of service but can expose sensitive information that was not intended to be publicly available.
OpenCVE Enrichment