Server-Side Request Forgery Vulnerability in Koel Music Streaming Solution
CVE-2026-50552
6.3MEDIUM
What is CVE-2026-50552?
Koel, an open-source music streaming platform, is vulnerable to a server-side request forgery (SSRF) in its radio station creation endpoint, potentially allowing authenticated non-admin users to trick the server into making unauthorized HTTP requests to internal systems. This arises because the validation rules for the URL field do not adequately prevent unsafe addresses from being queried. The issue was resolved in version 9.7.1, emphasizing the need for users to update to protect their applications.
Affected Version(s)
koel < 9.7.1
