CVE-2026-77385
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.34%
- Percentile among all scored CVEs: 25
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement75 % - Primary impact
T1005Data from Local Systemcollection80 % - Secondary impact
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access60 %
Usuario registrado explota validación de ruta incompleta (CWE-639, CWE-862) para acceder sin autorización a archivos ocultos o no catalogados en el servidor. AV:N/PR:L permite a usuario autenticado comprometer la aplicación web directamente.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-639, CWE-862
References
- https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91
- https://github.com/zoriya/Kyoo/pull/1577
- https://github.com/zoriya/Kyoo/releases/tag/v5.1.0
- https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46
- https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46
Raw JSON (NVD)
Show
{
"id": "CVE-2026-77385",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-77385",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-18T19:52:23.748951Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "zoriya",
"product": "Kyoo",
"versions": [
{
"status": "affected",
"version": "< 5.1.0"
}
]
}
]
}
],
"published": "2026-09-18T18:17:14.357",
"references": [
{
"url": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zoriya/Kyoo/pull/1577",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-639"
},
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0."
}
],
"lastModified": "2026-09-23T18:12:04.247",
"sourceIdentifier": "security-advisories@github.com"
}