SABnzbd 5.1.1 and 5.1.2 resolved 3 serious vulnerabilities.
You are only affected if an untrusted party can reach the web interface.
By default, SABnzbd is only accessible from your own device and External internet access
is set to No access. If either of those is still at its default, or if you use a proxy
service for authentication, you are not affected.
In version 5.1.1 and earlier, an attacker who can reach the web interface could bypass
authentication on configuration endpoints, even when SABnzbd is protected with a username
and password. By changing SABnzbd's settings this way, an attacker could ultimately execute
arbitrary commands on the system running SABnzbd, with the same permissions as SABnzbd itself.
This also means that all information in SABnzbd would be exposed.
See GHSA-xrfq-jhgh-wqch below for actions and mitigations.
More information: https://sabnzbd.org/5-1-vulnerabilities
You are affected if SABnzbd processes NZBs or downloads from a source you do not fully
trust, such as a public indexer.
In version 5.1.1 and earlier, a maliciously crafted PAR2 or SFV file inside a download
could cause SABnzbd to move downloaded content outside of the job's own folder during
post-processing. By using this to plant a file in another job's internal administration,
an attacker could ultimately execute arbitrary commands on the system running SABnzbd,
with the same permissions as SABnzbd itself.
The only mitigation is to update, there is no configuration change that prevents this.
More information: https://sabnzbd.org/5-1-vulnerabilities
You are only affected if an untrusted party can reach the web interface.
By default, SABnzbd is only accessible from your own device and External internet access
is set to No access. If either of those is still at its default, or if you use a proxy
service for authentication, you are not affected.
If the SABnzbd login page is reachable from outside your network, an attacker could
obtain a valid session in version 5.1.0 and earlier, even when SABnzbd is protected with
a username and password. This means that all information in SABnzbd would be exposed.
If you rely on the SABnzbd username and password to keep out other users on your
network or the internet, it is recommended that you change the following
sensitive information after applying the update:
If you cannot update right away, the only mitigations are to ensure the web interface is not
reachable by untrusted parties, or to lower External internet access to Full API or below.
More information: https://sabnzbd.org/5-1-vulnerabilities
Clear Downloaded button did not do anything.This release brings a fundamental improvement to "Retry": instead of
re-downloading any files with missing data, only the articles that were actually
missing are fetched again. RSS got an overhaul under the hood, the interface is
refreshed, and we added quite a long list of long-requested features and bugfixes.
Age rule to filter jobs based on their age.Cleanup List.Unwanted extensions will also be removed after unpacking.Extra queue columns..tar files during post-processing.Show Logging.SAB_FILES environment variable to Post-processing scripts,Ignore Samples detection.INSTALL.txt file.Cleanup List logic.Disk Full errors from unrar were not handled gracefully during unpacking.Moving stage.Queue repair.ISSUES.txt or https://sabnzbd.org/wiki/introduction/known-issuesWindows code signing is provided by SignPath.io using a SignPath Foundation certificate.
SABnzbd is an open-source cross-platform binary newsreader.
It simplifies the process of downloading from Usenet dramatically, thanks to its web-based
user interface and advanced built-in post-processing options that automatically verify, repair,
extract and clean up posts downloaded from Usenet.
(c) Copyright 2007-2026 by The SABnzbd-Team (sabnzbd.org)