30
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
Jellyfin 12.0 ships security fixes for path traversal, first-run setup bypass, unsafe plugin names, and web client XSS, plus removal of legacy login paths.
Jellyfin 12.0 blocks requests built to reach files outside served folders, prevents setup-wizard re-runs on misconfigured servers, rejects unsafe plugin package names, and fixes web client cross-site scripting. The project published no CVE identifiers or severity ratings for the fixes. The release also drops legacy /emby/ and /mediabrowser/ endpoints, targets .NET 10, and breaks 10.11-era third-party plugins.
28
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
30
45
30
30
30
30
30
45
30
30
30
45
30
30
30
30
30
30
30
30
45