Security Vulnerability in Koel Music Streaming Solution by Koel
CVE-2026-54492
4.3MEDIUM
What is CVE-2026-54492?
The Koel music streaming solution prior to version 9.7.0 contains a vulnerability in the Subsonic-compatible createPodcastChannel.view route. This issue arises because the application does not enforce SafeUrl validation on an authenticated user's private URL. Consequently, the PodcastService processes this URL, leading to potential blind internal request execution. Although generic response-body exfiltration has not been demonstrated, this vulnerability allows unauthorized requests to loopback or local network destinations, raising significant security concerns. The vulnerability has been addressed in version 9.7.0.
Affected Version(s)
koel < 9.7.0
