Authentication Bypass Vulnerability in Navidrome Music Server
CVE-2025-27112
6.9MEDIUM
Key Information:
- Vendor
- Navidrome
- Status
- Navidrome
- Vendor
- CVE Published:
- 24 February 2025
Summary
Navidrome, an open-source web-based music collection server, has a vulnerability in certain Subsonic API endpoints that allows an attacker to bypass authentication. Versions from 0.52.0 to prior 0.54.5 are affected, enabling an attacker to use any arbitrary username alongside a salted hash of an empty password to gain access to restricted endpoints. This flaw permits unauthorized viewing of read-only data, such as user playlists, while limiting the potential for data modification due to access controls. Users should upgrade to version 0.54.5 or later, where the issue has been addressed.
Affected Version(s)
navidrome >= 0.52.0, < 0.54.5
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved