THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73291 (HIGH 7.1) — Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarp

[NVD] CVE-2026-73291 (HIGH 7.1) — Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarp

lownvdPublished 2026-08-12

CVE-2026-73291 CVSS: 7.1 HIGH Published: 2026-08-12T15:18:33.020

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId route, allowing a malicious or co

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73291