PT-2026-34561 · Postgresql Global Development Group+1 · Postgresql+1

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-41167

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jellystat versions prior to 1.1.10
Description Multiple API endpoints build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via endpoints 'POST /api/getUserDetails' and 'POST /api/getLibrary', allowing full read access to any database table, including app config which contains admin credentials, the Jellyfin API key, and the Jellyfin host URL. Since the application uses the simple query protocol of node-postgres without a parameter array, stacked queries are possible. This allows the escalation from data disclosure to arbitrary command execution on the PostgreSQL host using COPY ... TO PROGRAM. When using the role provided in the docker-compose.yml file, which is a PostgreSQL superuser, no further privileges are needed for this execution.
Recommendations Update to version 1.1.10.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41167

Affected Products

Jellystat
Postgresql