CVE-2026-41167 — Jellystat: Because the vulnerable call site dispatches via `node-postgres`'s simple query protocol (no parameter array
Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetails` and `POST /api/getLibrary`, enabling full read of any table in the database - including `app_config`, which stores the Jellystat admin credentials, the Jellyfin API key, and the CVSSv3.1 9.1 (CRITICAL)