Affected Systems
FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.
Exploitation Status
Vulnerability has been fixed by FFmpeg. No CVE assigned yet. Active exploitation status unknown. Public disclosure suggests proof-of-concept may exist or be imminent given the vulnerability has been named and disclosed.
Business Impact
Organizations running Jellyfin servers face remote code execution risk, potentially allowing attackers to gain control of media servers and access underlying systems. Applications using FFmpeg for media processing (Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio) are vulnerable to denial-of-service attacks that could disrupt media services, file sharing, and streaming workflows. Specific FFmpeg version numbers and patch details not yet published.
Urgency
🟠Within 24 hours
Recommended Actions
- Identify all systems running Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio in your environment
- Monitor vendor security advisories for each affected application for patched versions incorporating fixed FFmpeg libraries
- Update FFmpeg to the latest version on systems where it is directly installed or compiled
- Restrict network access to Jellyfin servers to trusted users only until patches are applied
- Monitor application logs for unusual crashes, media processing errors, or unexpected resource consumption that may indicate exploitation attempts