VYPR

Kyoo

by Zoriya

CVEs (1)

  • CVE-2026-77386MedSep 18, 2026
    risk 0.35cvss 6.5epss

    Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored that URL with the opaque login state, and…