Wizarr Template Injection Flaw Allows Remote Code Execution
Worried this affects your website?
Wizarr, an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers, has a template injection vulnerability prior to 2026.9.1.
Wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator importing an untrusted bundle through POST /settings/wizard/import, could execute arbitrary Python when GET /wizard/{server}/{idx} rendered the stored step; app/jinja_filters.py and app/services/wizard_widgets.py contained additional evaluation sinks.
This could lead to:
- Execution of operating-system commands as the application user
- Disclosure of the Flask SECRET_KEY
- Access to connected service credentials and the database
- Stored cross-site scripting
The issue is fixed in 2026.9.1.
Reference: CVE-2026-108264 on NVD
← Back to Security News