Server-Side Request Forgery Vulnerability in Sonicverse Radio Audio Streaming Stack
CVE-2026-40089
9.9CRITICAL
What is CVE-2026-40089?
The Sonicverse Radio Audio Streaming Stack is susceptible to a Server-Side Request Forgery (SSRF) due to inadequate validation of user-controlled URLs in its API client. When using the provided installation script, authenticated users can exploit this vulnerability by sending crafted HTTP requests from the dashboard backend to both internal and external systems. This poses a significant risk as it allows unauthorized access to critical server resources, potentially exposing sensitive information.
Affected Version(s)
audiostreaming-stack < cb1ddbacafcb441549fe87d3eeabdb6a085325e4
