Vulnerability in Koel Music Streaming Solution Affects Private IP Handling
CVE-2026-54494
5.3MEDIUM
What is CVE-2026-54494?
Koel, a free and open-source music streaming application, has an input validation vulnerability affecting versions prior to 9.7.1. The issue lies in the App\Helpers\Network::isPublicHost() method, which misinterprets NAT64 and 6to4 wrapped private or loopback IPv4 addresses as public. This flaw enables an authenticated user to exploit the system by modifying podcast RSS entries, allowing access to the app/Values/Podcast/EpisodePlayable.php endpoint. Consequently, Koel may unintentionally access internal services or cloud metadata and expose the responses to the user, representing a significant security risk. The vulnerability was rectified in version 9.7.1.
Affected Version(s)
koel < 9.7.1
