Kerem 🛡 Cyber Security Engineer[verified]@keraattinDisclosure
The post announces the discovery of a critical remote code execution flaw in Jellyfin Media Server, outlining the attack vector and potential impact, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.
IntegSec[verified]@integ_secGeneral
The available text only contains a headline about Jellyfin’s path‑traversal vulnerability, with no details on PoC, exploitation, patches, or technical specifics.
0day Signal@0dayPublishingDisclosure
The tweet announces a Jellyfin vulnerability (CVE-2026-35031) that can lead to remote code execution via path traversal and .strm file chaining, with a link suggesting a proof of concept exists.
CTIWatch@ctiwatchcloudGeneral
The tweet lists three high‑CVSS CVEs and a link to a vulnerability portal, but does not include PoC, exploit details, active exploitation, or patch information.
CVE@CVEnewDisclosure
The text announces a known vulnerability in Jellyfin versions before 10.11.7, detailing its location in the subtitle upload endpoint, but does not provide PoC, exploit, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The tweet announces a newly identified vulnerability (CVE-2026-35031) in Jellyfin that permits arbitrary file writes and remote code execution, providing a link to details but no PoC, exploit code, or mitigation.