if they got in…
You’re trusting Jellyfin to not have some form of privilege escalation attack available. I’m not saying they do have one or that anyone’s exploiting it in the field, but yeah. Also if your Jellyfin admin account is allowed to download subtitles to content folders, a “just fuck shit up” style vandal-hacker could delete your media probably. If you mount the media read-only that wouldn’t be a concern.
A second device on site is still infinitely more resilient than just letting it rock. Most use cases where a backup would help can be covered by an occasional one way sync or scheduled copy to a USB drive. Offsite is for catastrophes like your home burning down or flooding.