Authentication Bypass Vulnerability in Navidrome Music Server
CVE-2025-27112
6.9MEDIUM
What is CVE-2025-27112?
Navidrome, an open-source web-based music collection server, has a vulnerability in certain Subsonic API endpoints that allows an attacker to bypass authentication. Versions from 0.52.0 to prior 0.54.5 are affected, enabling an attacker to use any arbitrary username alongside a salted hash of an empty password to gain access to restricted endpoints. This flaw permits unauthorized viewing of read-only data, such as user playlists, while limiting the potential for data modification due to access controls. Users should upgrade to version 0.54.5 or later, where the issue has been addressed.
Affected Version(s)
navidrome >= 0.52.0, < 0.54.5
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved