CVE-2026-31852 | Jellyfin GitHub Action code-quality.yml privileges management (GHSA-7qhm-2m45-7fmh / EUVD-2026-11242)
A vulnerability was found in Jellyfin. It has been rated as critical. Affected by this issue is some unknown functionality of the file code-quality.yml of the component GitHub Action Handler. The manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-31852. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.