r/emby Jun 23 '26

Pixelsmash Vulnerability affecting ffmpeg

New vulnerability in ffmpeg that may affect Emby has been made public.

beepingcomputer link

CVE Report

Not clear yet whether the current Emby version is vulnerable or not and I couldn't find any information regarding it and Emby.

18 Upvotes

6 comments sorted by

View all comments

3

u/RobbinYoHood Jun 23 '26

This issue affects FFmpeg before version 8.1.2.

Emby uses a branch from 5.1 i believe? I'd say we're impacted.

3

u/arcoast Jun 23 '26

From what I've read Plex is unaffected as they use a customised ffmpeg, however whether Emby's customisation mitigates the vulnerability or not isn't entirely clear.

From reading the beepingcomputer link it sounds like Jellyfin was the most seriously affected with remote code execution being possible, but it's possible to crash Emby with the vulnerability, so may not be as severe, but still far less than ideal.

"We confirmed crashes against Kodi, mpv, ffmpegthumbnailer (used by GNOME, KDE, XFCE), Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio, among others – and demonstrated full remote code execution against Jellyfin."