In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
{ "versions": [ { "introduced": "10.8.0" }, { "last_affected": "10.8.3" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-23635.json"