HomeSecurityPixelSmash: Critical vulnerability in FFmpeg allows RCE

PixelSmash: Critical vulnerability in FFmpeg allows RCE

PixelSmash is the name of a new, serious vulnerability discovered in FFmpeg that can lead to remote code execution (RCE) on Jellyfin servers , as well as denial-of-service (DoS) in popular applications such as Kodi , Emby , Nextcloud , PhotoPrism, and OBS Studio . The vulnerability is tracked as CVE-2026-8461 and concerns a heap out-of-bounds write in FFmpeg's MagicYUV decoder . It has received a CVSS score of 8.8 (High). Any application that uses FFmpeg's libavcodec library is considered vulnerable.

PixelSmash CVE-2026-8461 FFmpeg MagicYUV decoder RCE vulnerability

The discovery was made by the JFrog Security Research , specifically by researcher Yuval Moravchick. PixelSmash can be triggered via a malicious video file in AVI, MKV , or MOV — even a file as small as 50 KB. The vulnerability was privately reported to the FFmpeg security team on May 13, 2026 , and was fixed with the release of FFmpeg version 8.1.2 on June 17, 2026.

See also: Vulnerability in Veeam Backup & Replication allows RCE attacks

The root of the problem lies in the way the MagicYUV decoder handles “slices” — independent regions of a video frame that are decoded separately. The MagicYUV decoder is enabled by default in FFmpeg versions, which significantly expands the number of affected systems.

PixelSmash: How attackers exploit the vulnerability

PixelSmash can be triggered in several ways: when the user opens a malicious video file , when browsing a folder containing the file (via thumbnail creation), or when any automated import media flow is executed . Researcher Yuval Moravchick demonstrated that PixelSmash can be used for RCE in Jellyfin and Nextcloud environments (with Movie preview enabled). Specifically, on a Jellyfin 10.11.9 media server, the exploit follows the following path: a malicious MagicYUV AVI file is downloaded to the media library, Jellyfin automatically triggers ffprobe to extract metadata, OOB write is executed, AVBuffer.free is “hacked” to call system() , and finally an arbitrary command is executed as the jellyfin service user.

A particularly worrisome attack scenario involves torrent downloads and requires no user interaction. An attacker could “seed” a malicious video targeting Jellyfin users, who would direct the downloads to the application’s media library folder. Jellyfin’s file tracking system would detect the new file and automatically trigger a metadata scan, during which the exploit would be executed. It is worth noting that the RCE exploit requires either disabled ASLR (Address Space Layout Randomization) or a combination with another vulnerability — theoretically, a separate information-disclosure bug in FFmpeg’s FlashSV decoder could be used to bypass ASLR.

See also: Langflow vulnerability used for RCE attacks

Even when RCE is not feasible, CVE-2026-8461 is enough to cause credible DoS attacks on vulnerable systems. Applications such as mpv, Kodi, OBS Studio and even the thumbnail generators of GNOME, KDE and XFCE are affected. Platforms such as Slack, Discord, Telegram and WhatsApp may also be vulnerable, as they use FFmpeg to generate video previews on the server side (although they have not been officially tested). A notable exception is Plex, which uses a custom version of FFmpeg with disabled decoders and a minimal allowlist, effectively mitigating the PixelSmash risk.

According to BleepingComputer, in addition to releasing FFmpeg 8.1.2 that fixes the vulnerability, Jellyfin has also updated the built-in FFmpeg version, while PhotoPrism is working on addressing the issue. Given that FFmpeg is the backbone of the multimedia industry, the potential number of affected systems is in the millions of devices worldwide — from media servers and desktops to cloud services.

See also: Vulnerability in LiteLLM leads to unauthenticated RCE

To protect against PixelSmash, system administrators should immediately upgrade to FFmpeg 8.1.2 or later. For systems that cannot be upgraded immediately, it is recommended to disable the MagicYUV decoder in the FFmpeg configuration. In addition, it is important to implement file block lists for AVI, MKV, and MOV files from untrusted sources, verify files before processing them, and ensure that ASLR is enabled on all servers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS