Description
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Disclosure
Action: Patch
AI Analysis

Impact

A missing catalog‑level authorization check in Kyoo’s transcoder allows a registered user with core.play permission to supply a base64‑encoded file system path. The transcoder normalises the path only to confirm it begins with the configured SafePath, but the downstream file‑serving logic does not verify that the requested file is part of the catalog. This enables the user to read any file within the media directory when the path is known or can be guessed. The consequence is the unauthorized disclosure of hidden, temporary, or operational files, reflecting weaknesses in CWE‑639 (Authorization Bypass through Privileged Credentials) and CWE‑862 (Missing Authorization).

Affected Systems

All Kyoo installations running a version earlier than 5.1.0 are affected, as the flaw sits in the core transcoder logic and is not gated by environmental configuration. The impact applies to any environment where the application runs and the media directory is accessible to the process, provided a user has the core.play permission.

Risk and Exploitability

The CVSS base score of 4.3 reflects a low overall risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a legitimate user account with core.play permission; the user can invoke the transcoder endpoint with a base64‑encoded path, bypassing catalog checks and retrieving arbitrary files beneath the media directory. Because the user role is restricted, exploitation depends on an attacker’s ability to obtain such credentials or compromise an existing account. The vulnerability does not grant remote code execution or denial of service but can expose sensitive information that was not intended to be publicly available.

Generated by OpenCVE AI on September 19, 2026 at 11:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Kyoo 5.1.0 or later, which corrects the path validation and catalog‑level authorization logic.
  • If an upgrade cannot be performed immediately, restrict or remove the core.play permission from untrusted users or disable transcoder functionality for those accounts.
  • Consider relocating the media directory to a separate, read‑only filesystem mount or applying stricter operating‑system permissions to limit file access to the Kyoo application process.

Generated by OpenCVE AI on September 19, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoriya
Zoriya kyoo
Vendors & Products Zoriya
Zoriya kyoo

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
Title Kyoo: Transcoder serves uncataloged files from the media directory
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T19:52:50.924Z

Reserved: 2026-08-20T19:36:13.806Z

Link: CVE-2026-77385

cve-icon Vulnrichment

Updated: 2026-09-18T19:52:44.333Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:17:14.357

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-77385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:04:27Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization