Search
Find a vulnerability
Search criteria
4 vulnerabilities by zoriya
CVE-2026-77386 (GCVE-0-2026-77386)
Vulnerability from nvd – Published: 2026-09-18 17:16 – Updated: 2026-09-22 15:09
VLAI
EPSS
VEX
Title
Kyoo: OIDC login token can be redirected to an attacker-controlled URL
Summary
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim's browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim's Kyoo session. This issue is fixed in version 5.1.0.
Severity
6.5 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:08 UTC
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/zoriya/Kyoo/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/zoriya/Kyoo/pull/1576 | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/commit/02ab3af8127… | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/releases/tag/v5.1.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77386",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:08:48.131175Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:09:09.067Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Kyoo",
"vendor": "zoriya",
"versions": [
{
"status": "affected",
"version": "\u003c 5.1.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim\u0027s browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim\u0027s Kyoo session. This issue is fixed in version 5.1.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:16:37.282Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
},
{
"name": "https://github.com/zoriya/Kyoo/pull/1576",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/pull/1576"
},
{
"name": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632"
},
{
"name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
}
],
"source": {
"advisory": "GHSA-xhg6-v78p-xf44",
"discovery": "UNKNOWN"
},
"title": "Kyoo: OIDC login token can be redirected to an attacker-controlled URL"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77386",
"datePublished": "2026-09-18T17:16:37.282Z",
"dateReserved": "2026-08-20T19:36:13.806Z",
"dateUpdated": "2026-09-22T15:09:09.067Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77385 (GCVE-0-2026-77385)
Vulnerability from nvd – Published: 2026-09-18 17:15 – Updated: 2026-09-18 19:52
VLAI
EPSS
VEX
Title
Kyoo: Transcoder serves uncataloged files from the media directory
Summary
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
Severity
4.3 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 19:52 UTC
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/zoriya/Kyoo/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/zoriya/Kyoo/pull/1577 | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/commit/c542adb5dc6… | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/releases/tag/v5.1.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77385",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T19:52:23.748951Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T19:52:50.924Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Kyoo",
"vendor": "zoriya",
"versions": [
{
"status": "affected",
"version": "\u003c 5.1.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:15:28.745Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
},
{
"name": "https://github.com/zoriya/Kyoo/pull/1577",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/pull/1577"
},
{
"name": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91"
},
{
"name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
}
],
"source": {
"advisory": "GHSA-fc8v-vr3q-hc46",
"discovery": "UNKNOWN"
},
"title": "Kyoo: Transcoder serves uncataloged files from the media directory"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77385",
"datePublished": "2026-09-18T17:15:28.745Z",
"dateReserved": "2026-08-20T19:36:13.806Z",
"dateUpdated": "2026-09-18T19:52:50.924Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77386 (GCVE-0-2026-77386)
Vulnerability from cvelistv5 – Published: 2026-09-18 17:16 – Updated: 2026-09-22 15:09
VLAI
EPSS
VEX
Title
Kyoo: OIDC login token can be redirected to an attacker-controlled URL
Summary
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim's browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim's Kyoo session. This issue is fixed in version 5.1.0.
Severity
6.5 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:08 UTC
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/zoriya/Kyoo/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/zoriya/Kyoo/pull/1576 | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/commit/02ab3af8127… | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/releases/tag/v5.1.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77386",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T15:08:48.131175Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:09:09.067Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Kyoo",
"vendor": "zoriya",
"versions": [
{
"status": "affected",
"version": "\u003c 5.1.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and /auth/oidc/logged/{provider} appended the provider, token, and error values before redirecting the victim\u0027s browser without validating the destination. Because the one-use token was not bound to the browser session that initiated login, an attacker who induced a victim to complete OIDC authentication could capture the token at the attacker-controlled destination and exchange it through /auth/oidc/callback/{provider} for the victim\u0027s Kyoo session. This issue is fixed in version 5.1.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:16:37.282Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-xhg6-v78p-xf44"
},
{
"name": "https://github.com/zoriya/Kyoo/pull/1576",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/pull/1576"
},
{
"name": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/commit/02ab3af8127a081295fd7bed103847173c0d7632"
},
{
"name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
}
],
"source": {
"advisory": "GHSA-xhg6-v78p-xf44",
"discovery": "UNKNOWN"
},
"title": "Kyoo: OIDC login token can be redirected to an attacker-controlled URL"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77386",
"datePublished": "2026-09-18T17:16:37.282Z",
"dateReserved": "2026-08-20T19:36:13.806Z",
"dateUpdated": "2026-09-22T15:09:09.067Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77385 (GCVE-0-2026-77385)
Vulnerability from cvelistv5 – Published: 2026-09-18 17:15 – Updated: 2026-09-18 19:52
VLAI
EPSS
VEX
Title
Kyoo: Transcoder serves uncataloged files from the media directory
Summary
Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0.
Severity
4.3 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 19:52 UTC
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/zoriya/Kyoo/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/zoriya/Kyoo/pull/1577 | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/commit/c542adb5dc6… | x_refsource_MISC |
| https://github.com/zoriya/Kyoo/releases/tag/v5.1.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77385",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T19:52:23.748951Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T19:52:50.924Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Kyoo",
"vendor": "zoriya",
"versions": [
{
"status": "affected",
"version": "\u003c 5.1.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src/api/path.go cleaned the value and checked only that it began with Settings.SafePath before getHash processed it, while transcoder/src/api/streams.go served the accepted path without verifying a Kyoo catalog record. This missing catalog-level authorization allowed the user to retrieve hidden, temporary, operational, or other uncataloged files beneath the media directory when the path was known or guessed. This vulnerability is fixed in 5.1.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:15:28.745Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/zoriya/Kyoo/security/advisories/GHSA-fc8v-vr3q-hc46"
},
{
"name": "https://github.com/zoriya/Kyoo/pull/1577",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/pull/1577"
},
{
"name": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/commit/c542adb5dc6d681e6491b28b5ac618c35c446d91"
},
{
"name": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/zoriya/Kyoo/releases/tag/v5.1.0"
}
],
"source": {
"advisory": "GHSA-fc8v-vr3q-hc46",
"discovery": "UNKNOWN"
},
"title": "Kyoo: Transcoder serves uncataloged files from the media directory"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77385",
"datePublished": "2026-09-18T17:15:28.745Z",
"dateReserved": "2026-08-20T19:36:13.806Z",
"dateUpdated": "2026-09-18T19:52:50.924Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}