• Sources: primary, discussion
  • Summary: Jellyfin 12.0 rewrites the library database on first start, with a manual backup as the only way back to the previous version. The upgrade requires a full library scan, removes the /emby/ and /mediabrowser/ routes, and breaks plugins built for 10.11. The release notes also list security fixes affecting 10.11.x and earlier: several paths by which a crafted request could reach files outside the directories Jellyfin serves, re-running the setup wizard on a misconfigured server without signing in, plugin packages with unsafe names, parental controls, and cross-site scripting in the web client. The project recommends upgrading for those fixes.
  • Why it matters: The upgrade is one-way in practice, so self-hosted operators need a verified backup and a plugin inventory before starting it, and the security fixes are an argument against deferring it indefinitely.

send feedback on this story