Comment on Jellyfin over the internet

<- View Parent
pory@lemmy.world ⁨5⁩ ⁨weeks⁩ ago

if they got in…

You’re trusting Jellyfin to not have some form of privilege escalation attack available. I’m not saying they do have one or that anyone’s exploiting it in the field, but yeah. Also if your Jellyfin admin account is allowed to download subtitles to content folders, a “just fuck shit up” style vandal-hacker could delete your media probably. If you mount the media read-only that wouldn’t be a concern.

source
Sort:hotnewtop