Server-Side Request Forgery in Sonaar MP3 Audio Player for Music, Radio & Podcast
CVE-2026-39647

5.4MEDIUM

What is CVE-2026-39647?

A Server-Side Request Forgery (SSRF) vulnerability in the Sonaar MP3 Audio Player for Music, Radio & Podcast plugin allows attackers to make unauthorized requests to internal services. This can lead to exposure of sensitive information and compromise of server resources. Versions from n/a to 5.11 are affected, making it crucial for users to apply patches to secure their installations against potential exploitation.

Affected Version(s)

MP3 Audio Player for Music, Radio & Podcast by Sonaar 0 <= 5.11

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

johska | Patchstack Bug Bounty Program
.