Vulnerability in Koel Music Streaming Solution Affects Private IP Handling
CVE-2026-54494

5.3MEDIUM

Key Information:

Vendor

Koel

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-54494?

Koel, a free and open-source music streaming application, has an input validation vulnerability affecting versions prior to 9.7.1. The issue lies in the App\Helpers\Network::isPublicHost() method, which misinterprets NAT64 and 6to4 wrapped private or loopback IPv4 addresses as public. This flaw enables an authenticated user to exploit the system by modifying podcast RSS entries, allowing access to the app/Values/Podcast/EpisodePlayable.php endpoint. Consequently, Koel may unintentionally access internal services or cloud metadata and expose the responses to the user, representing a significant security risk. The vulnerability was rectified in version 9.7.1.

Affected Version(s)

koel < 9.7.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.