How come this is not an issue for other projects then? Why isn't Overseer also saying "don't host this publicly because we can't also can't guarantee perfect security? Is the issue really just that they can't prove security or is there an actual security issue with the API? From what you're saying it sounds like the only issue is that they haven't done an audit but that it's otherwise fine, but other people are saying there are actual security holes regardless of whether an audit is performed.
Like, I'm fine running stuff publicly that hasn't been audited like most of the stuff I self host. Why are people treating jellyfin differently than other self hosted projects that haven't been audited?