• ligma_centauri@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 hours ago

    Just did a cursory read of the commits related to security for this release, and my assumpion based solely on the changes, is that it’s not a remote-access vulnerability, but a supply-chain-esque vulnerability where a video you downloaded from a questionable source might trigger code embedded in the metadata to be run by jellyfin.