Authentication Bypass Vulnerability in Navidrome Music Server
CVE-2025-27112
What is CVE-2025-27112?
Navidrome, an open-source web-based music collection server, has a vulnerability in certain Subsonic API endpoints that allows an attacker to bypass authentication. Versions from 0.52.0 to prior 0.54.5 are affected, enabling an attacker to use any arbitrary username alongside a salted hash of an empty password to gain access to restricted endpoints. This flaw permits unauthorized viewing of read-only data, such as user playlists, while limiting the potential for data modification due to access controls. Users should upgrade to version 0.54.5 or later, where the issue has been addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
navidrome >= 0.52.0, < 0.54.5
References
EPSS Score
12% chance of being exploited in the next 30 days.
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
