Elektrine lite

← Feed

@Morgikan@fedia.io

Post #3785418

2026-07-06 05:13 UTC

It would depend on having access to misconfigured permissions or docker.sock like when you chain containers to manage other containers. Because you have access to docker.sock and that socket can send API calls to the docker daemon (which is run from root) those commands would inherit the same level of access. An attacker could make the API call to mount /:/root and then access the host filesystem. It's just an example of how even though the container might not have anything worthwhile, it can be used to laterally move and open another door.

Replies (1)

  • @hirihit640@sh.itjust.works 2026-07-06 05:36

    Got it. Access to docker.sock is definitely something to be wary of, or CAP_ADMIN, or access to certain host devices. Worth mentioning though that Jellyfin usually has none of these.

    Open ##3794829