CRITICAL 9.1 CVE-2026-108264 Published 9 Oct 2026

Wizarr Template Injection Flaw Allows Remote Code Execution

Worried this affects your website?

Wizarr, an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers, has a template injection vulnerability prior to 2026.9.1.

Wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator importing an untrusted bundle through POST /settings/wizard/import, could execute arbitrary Python when GET /wizard/{server}/{idx} rendered the stored step; app/jinja_filters.py and app/services/wizard_widgets.py contained additional evaluation sinks.

This could lead to:

  • Execution of operating-system commands as the application user
  • Disclosure of the Flask SECRET_KEY
  • Access to connected service credentials and the database
  • Stored cross-site scripting

The issue is fixed in 2026.9.1.

Reference: CVE-2026-108264 on NVD

← Back to Security News