Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the Wizarr system, which manages user invitations for media servers like Jellyfin and Plex, allows authenticated users to execute arbitrary code. This could lead to the disclosure of sensitive information, access to credentials, and the execution of operating system commands.
- System allows unauthorized code execution.
- Affects internet-facing invitation management.
- Confirm relevance and exposure of system.
Attack Path
How an attacker could exploit the issue
An attacker could target the Wizarr system by crafting malicious Markdown content within wizard steps, either directly through the editor or by importing an untrusted bundle. This crafted content would be processed by the application's non-sandboxed Jinja2 environment, allowing for arbitrary Python code execution. The vulnerability can lead to the disclosure of sensitive information, access to connected service credentials and databases, and the execution of operating-system commands as the application user.
- Authenticated user or administrator with import privilege.
- Crafted Markdown in wizard steps or imported bundles.
- Arbitrary code execution and data compromise.
Live Threat
Current exploitation, exposure, and threat context
An authenticated user with the ability to create wizard steps or import untrusted bundles could execute arbitrary Python code within the application's non-sandboxed environment. This could lead to the execution of operating-system commands, disclosure of sensitive information like the Flask SECRET_KEY and connected service credentials, and potential stored cross-site scripting vulnerabilities.
- System commands and Flask SECRET_KEY.
- Arbitrary Python execution via crafted wizard steps.
- Compromise of credentials and server data.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Wizarr application's potential for arbitrary code execution and data compromise necessitates immediate action. Owners of media server deployments utilizing Wizarr, particularly those accessible externally, should prioritize identifying all instances of the affected technology, assessing their exposure, and confirming business criticality. This initial triage will inform the subsequent remediation planning, which may involve vendor coordination or temporary risk reduction measures.
- Identify Wizarr instances and their owners.
- Verify external reachability and business criticality.
- Plan remediation based on confirmed risk.