Missing Authentication Vulnerability in Podgrab by Podgrab Team
CVE-2026-104058
What is CVE-2026-104058?
Podgrab is affected by a missing authentication issue where the /ws WebSocket route is improperly registered on the root gin engine, rather than being secured by the BasicAuth-protected router group. This oversight enables unauthenticated network clients to connect, even when a PASSWORD is set. Consequently, attackers can join the allConnections set and intercept PlayerExists broadcasts containing identifiers supplied by legitimate clients. They can exploit this flaw to hijack queue payloads directed at authenticated users, gaining unauthorized access to sensitive information such as episode IDs, titles, and server-side file paths, thereby potentially disrupting normal playback experiences.
Affected Version(s)
podgrab 0 <= 032248091294dbf5b6a439a5afd93788a7cc647f
