CVE-2026-31852Disclosure(jellyfin / jellyfin)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch jellyfin jellyfin systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this vulnerability enables full repository takeover of jellyfin/jellyfin-ios, exfiltration of highly privileged secrets, Apple App Store supply chain attack, GitHub Container Registry (ghcr.io) package poisoning, and full jellyfin organization compromise via cross-repository token usage. Note: This is not a code vulnerability, but a vulnerability in the GitHub Actions workflows. No new version is required for this GHSA and end users do not need to take any actions.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jellyfin

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-11); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
jellyfin

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 2Mentions · 2026-05-20: 1Mentions · 2026-09-06: 2PoC Mentioned / Linked · 2026-03-11: 1PoC Mentioned / Linked · 2026-09-06: 1Exploit Tool / Code · 2026-09-06: 1Active Exploitation · 2026-03-11: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 2Technical Details · 2026-05-20: 103-1103-1205-2009-06
Signal classification4 categories
Disclosure
450.0%
Exploit
225.0%
Patch
112.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure2Exploit1
2026-03-122
Disclosure2
2026-05-201
Patch1
2026-09-062
Exploit1General1
Full discourse8 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-31852 - Critical supply chain attack in Jellyfin iOS. GitHub Actions workflow allows repo takeover, secret exfiltration, and App Store poisoning. CVSS 10. UNPATCHED. Disable workflow immediately. #CVE #jellyfin #infosec #cybersecurity More: https://www.valtersit.com/cve/CVE-2026-31852/

    Post summary

    A critical supply‑chain vulnerability (CVE‑2026‑31852) affecting Jellyfin iOS enables repo takeover and secret exfiltration via a GitHub Actions workflow; operators are advised to disable the workflow as a temporary mitigation while a patch is pending.

    00020233
    985 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-eHuX12n [CRITICAL/PoC] Linked: CVE-2026-31852 gha-lab-3f1ff30e9c 🔗 https://exploitgrid.net/exploits/83ead7a8-5357-4d9e-a30a-ca9d6ae9c0a9

    Post summary

    The post announces a critical PoC for CVE‑2026‑31852 and provides a link to a functional exploit on ExploitGrid.

    1000047
    40 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-27941 CVE-2026-31852 CVE-2026-56290 CVE-2026-7873 CVE-2023-42793 ..🧵👇

    Post summary

    The post lists several CVEs without providing any additional technical, exploitation, or remediation details.

    1000049
    40 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-31852: Jellyfin Possible Organization/S... Fork a PR, own the entire Jellyfin org - GitHub Actions with write-all perms just handed attackers the keys to Apple Ap... https://zerodaysignal.com/vulnerability/CVE-2026-31852 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-31852 exposes a GitHub Actions flaw that lets attackers fork an org’s PR and gain full write access, effectively stealing Apple App keys; the tweet indicates the vulnerability is actively being exploited with no patch discussed.

    0001069
    143 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31852 Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requ… https://www.cve.org/CVERecord?id=CVE-2026-31852 ----- Traducción: CVE-2026-31852 Jel… http://infoflow.cloud`

    Post summary

    The tweet announces the CVE‑2026‑31852 vulnerability, noting it enables arbitrary code execution via the Jellyfin iOS GitHub Actions workflow, with no evidence of a PoC, exploit, patch, or active exploitation.

    0000048
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31852 Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requ… https://www.cve.org/CVERecord?id=CVE-2026-31852

    Post summary

    The post announces CVE‑2026‑31852 affecting Jellyfin’s GitHub Actions workflow, indicating arbitrary code execution via pull requests, but does not provide PoC, exploit, patch, or active exploitation details.

    00000244
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-31852: CRITICAL] Critical vulnerability in Jellyfin's GitHub Actions workflow allows for code execution & repository takeover. Potential risks include supply chain attack & organization compromise....#cve,CVE-2026-31852,#cybersecurity https://cvefind.com/CVE-2026-31852

    Post summary

    A critical (CVE-2026-31852) vulnerability in Jellyfin's GitHub Actions workflow, enabling code execution and repository takeover, has been disclosed.

    0000053
    602 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31852 - Critical Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repo... https://www.thehackerwire.com/vulnerability/CVE-2026-31852/ https://t.co/91OjuhUN8L

    Post summary

    The tweet announces CVE-2026-31852, noting that Jellyfin’s GitHub Actions workflow is vulnerable to arbitrary code execution via pull requests from forked repos, and points to a vulnerability report without mentioning a PoC, exploit, or patch.

    0000055
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjellyfinjellyfin---

Explore more