# Jellyseerr v3.4.0 — Release v3.4.0 - Product: Jellyseerr (https://whatsnew.fyi/product/jellyseerr) - Vendor: Jellyseerr - Date: 2026-07-28 - Version: v3.4.0 - Original notes: https://github.com/seerr-team/seerr/releases/tag/v3.4.0 - Permalink: https://whatsnew.fyi/product/jellyseerr/releases/v3.4.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Patch path traversal vulnerability leading to remote code execution in the ImageProxy - **added** — Add user details sync functionality to PlexImportModal - **added** — Support userId parameter when creating issues via API - **added** — Add Simkl media link to external links - **added** — Add Discord thread ID support for notifications - **added** — Allow admins to bypass user quota limits for requests - **added** — Add option to disable version check - **added** — Add Jellyfin/Emby quick connect authentication - **fixed** — Prevent false removals for merged-version Plex items in availability sync - **fixed** — Use added sort in recent requests slider on discover page - **fixed** — Respect hosts file for SMTP connections in email - **fixed** — Fallback to server locale for Default user language in notifications - **fixed** — Make Discord IDs available even when notification is disabled on Seerr - **fixed** — Proxy clients built before proxy initialization - **fixed** — Decline orphaned requests when media is removed from Servarr - **fixed** — Await request status updates in subscriber - **fixed** — Revalidate request list after approving or declining a request - **fixed** — Guard web push subscriptions request until user loads - **fixed** — Support IPv6 address literals in HOST environment variable - **fixed** — Prevent cross-instance external ID collisions ##### [3.4.0](https://github.com/seerr-team/seerr/compare/v3.3.0..v3.4.0) - 2026-07-28 This release patches a path traversal vulnerability in the avatar image proxy. Exploitation vectors: - A malicious or compromised Jellyfin/Emby media server returning a crafted HTTP response. - A man-in-the-middle attacker intercepting the connection to the media server, if it is configured over HTTP instead of HTTPS (the default setting). ###### 🛡️ Security - Patch [GHSA-mc6w-69r3-62h8](https://github.com/seerr-team/seerr/security/advisories/GHSA-mc6w-69r3-62h8) - Path Traversal leading to Remote Code Execution vulnerability (in seerr's ImageProxy) - ([f484791](https://github.com/seerr-team/seerr/commit/f484791105bd81bd5404e01410431ee6fe5769c2)) ###### 🚀 Features - *(PlexImportModal)* Add user details sync functionality (#2977) - ([902b88e](https://github.com/seerr-team/seerr/commit/902b88e16a0075da8831e6293954bdfafd6db4d8)) - *(api)* Support `userId` when creating issues (#3100) - ([5f2722d](https://github.com/seerr-team/seerr/commit/5f2722da30ba000f2d07ddaa099c7d6416378458)) - *(external-links)* Add Simkl media link (#3121) - ([5ae70d0](https://github.com/seerr-team/seerr/commit/5ae70d05e1ee123b3cda43153ed415754fd8e816)) - *(notifications)* Add Discord thread ID support (#3065) - ([6e9ba06](https://github.com/seerr-team/seerr/commit/6e9ba06e88d283c4c5c409c9fdac6d74ed8feaa1)) - *(requests)* Allow admins to bypass user quota limits (#2026) - ([72536da](https://github.com/seerr-team/seerr/commit/72536da50ea97278b0330ccc42c5b33fb864000b)) - Allow to disable version check (#3137) - ([73937c0](https://github.com/seerr-team/seerr/commit/73937c0ccd667daed67e320a7fbc032b1207ef53)) - Add jellyfin/emby quick connect authentication (#2212) - ([74c8db4](https://github.com/seerr-team/seerr/commit/74c8db42a643c2c63e16cdd58ba790f6adfb7ab5)) ###### 🐛 Bug Fixes - *(availability-sync)* Prevent false removals for merged-version Plex items (#3224) - ([46d8033](https://github.com/seerr-team/seerr/commit/46d80335991cc7c5a9e1c501e274f5a90a6c07c9)) - *(discover)* Use added sort in recent requests slider (#3202) - ([8ccd0f6](https://github.com/seerr-team/seerr/commit/8ccd0f624530035089998e76b57a627f58c7eb7f)) - *(email)* Respect hosts file for SMTP connections (#3082) - ([b660201](https://github.com/seerr-team/seerr/commit/b66020128bdc6bca4de9ec2577e122d8f6d29139)) - *(i18n)* Fallback to server locale for "Default" user lang in notifs (#3190) - ([ef9edc8](https://github.com/seerr-team/seerr/commit/ef9edc832fa5efed53e330563e6db1fddbb44cf4)) - *(next)* Add next-env.d.ts to .gitignore (#3282) - ([3279393](https://github.com/seerr-team/seerr/commit/3279393c7914c1d73af24ddc8252ce9fff8966e6)) - *(notifications)* Make the Discord IDs available even when the notification is disabled on Seerr (#3139) - ([a8f1780](https://github.com/seerr-team/seerr/commit/a8f1780bee589cdce5544356212a4dd2272d94e0)) - *(proxy)* Proxy clients built before proxy init (#3196) - ([8ad191f](https://github.com/seerr-team/seerr/commit/8ad191f42b5c58032d609b1eef38c3a1ae3ab23a)) - *(scanners)* Decline orphaned requests when media is removed from servarr (#3191) - ([2e0e4ce](https://github.com/seerr-team/seerr/commit/2e0e4ceb2a0100bd411e6432b1d5c5e3a553644c)) - *(subscriber)* Await request status updates (#3223) - ([f481b56](https://github.com/seerr-team/seerr/commit/f481b56a7ac30444551b28508e30eeb415716a3c)) - *(ui)* Revalidate request list after approving or declining a request (#3283) - ([e810b98](https://github.com/seerr-team/seerr/commit/e810b9814d2b41ef31630f09b5dd0da1e9dec690)) - *(webpush)* Guard subscriptions request until user loads (#3113) - ([6829850](https://github.com/seerr-team/seerr/commit/6829850bbcddb9f0fdddf0fe6ef483566050d566)) - Support for IPv6 address literals in HOST env var (#2614) - ([0adbf50](https://github.com/seerr-team/seerr/commit/0adbf50b5c448cc5ca928480017890abb2dc5776)) - Prevent cross-instance external ID collisions (#3203) - _[Truncated at 4000 characters — full notes: https://github.com/seerr-team/seerr/releases/tag/v3.4.0]_