Security: morpheus65535/bazarr
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Arbitrary File Deletion via Unvalidated subtitles_path in Episodes/Movies Blacklist API (Sibling of GHSA-2p5v-r635-q9hv, Not Covered by Its Fix)GHSA-mpj5-vvxw-pvr4 published
Sep 21, 2026 by morpheus65535High -
Arbitrary file deletion via the path parameter of the subtitles delete APIGHSA-2p5v-r635-q9hv published
Sep 20, 2026 by morpheus65535High -
Bazarr PWA asset route allows unauthenticated arbitrary file read on WindowsGHSA-v569-4w84-grxq published
Aug 23, 2026 by morpheus65535High -
Authentication bypass leading to information disclosure, SSRF, and remote code executionGHSA-jcpg-cp8q-738f published
Aug 3, 2026 by morpheus65535Critical -
Bazarr: OS Command Injection via Subtitle Metadata in Post-Processing (Windows, Regression of Prior CWE-78 Fix)GHSA-9vfg-76hq-g7cw published
Jul 19, 2026 by morpheus65535High -
Plex OAuth API namespace is entirely unauthenticated, allowing config tampering, integration takeover and server-side request forgeryGHSA-fvcv-hh55-x3r4 published
Jun 24, 2026 by morpheus65535Critical
Learn more about advisories related to morpheus65535/bazarr in the GitHub Advisory Database