Authorization Flaw in Koel Music Streaming Solution
CVE-2026-54493

7.7HIGH

Key Information:

Vendor

Koel

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-54493?

Koel, an open-source music streaming platform, has a security vulnerability in its routes for creating and updating Internet radio stations. Authenticated users could exploit this flaw to stream arbitrary URLs without proper validation checks. The affected functionality allowed users to bypass the SafeUrl and HasAudioContentType checks, compromising the security of internal HTTP services reachable from the Koel server. This weakness is addressed in version 9.7.0, reinforcing the importance of keeping software updated to mitigate potential security risks.

Affected Version(s)

koel < 9.7.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.