CVE-2026-77385
Last modified
CVE-2026-77385 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zoriya | Kyoo | < 5.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-77385?
How severe is CVE-2026-77385?
How do I fix CVE-2026-77385?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77360oRPC is an tool that helps build APIs that are end-to-end ty…6.3
- CVE-2026-77365The Optimole – Optimize Images | Convert WebP & AVIF | CDN &…7.2
- CVE-2026-77368SeaweedFS is a distributed storage system for files and blob…7.6
- CVE-2026-7737A vulnerability was identified in osrg GoBGP up to 4.3.0. Af…7.5
- CVE-2026-7738A security flaw has been discovered in puchunjie doc-tools-m…6.3
- CVE-2026-77384libp2p is a JavaScript implementation of the libp2p networki…7.5
- CVE-2026-77386Kyoo is a self-hosted media server focused on movies, series…6.5
- CVE-2026-7739A weakness has been identified in justdan96 tsMuxer up to 2.…3.3
- CVE-2026-77391A security flaw has been discovered in SourceCodester Dynami…4.3
- CVE-2026-77392A weakness has been identified in SourceCodester Dynamic Inp…6.3
- CVE-2026-77393In Ignition 8.1.53 and earlier, the Gateway "Create Project …8.8
- CVE-2026-77394OpenC3 COSMOS provides the functionality needed to send comm…7.6
Are you affected by CVE-2026-77385?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
