It matters if someone manages to hide an exploit in jellyfin’s codebase, or more likely, a popular plugin. I imagine many folk have permissive outgoing firewall rules, in which case, an exploit could establish connectivity. Whether that eventually leads to privilege escalation on the jellyfin host would depend upon other variables.
edit: I should add that I’ve not used jellyfin and am unfamiliar with how plugins are implemented. I don’t want to speak out of turn, only to suggest, in the abstract, that just because software isn’t exposed to the net, doesn’t mean it cannot harbor exploits that could become problematic. Plugins just seem to be a common vector for such types of software.
Many years ago, I scooped up my lifetime plex sub for I believe $100. But, when plex started pushing their own login portal, I grew wary and bitter. I outright deleted my account shortly thereafter. I more or less respect the hustle but not my cup of tea.