Description
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials. This issue has been patched in version 0.60.0.
Problem types
CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
References
github.com/...idrome/security/advisories/GHSA-rh3r-8pxm-hg4w
github.com/...ommit/d7ec7355c9036d5be659d6ac555c334bb5848ba6
github.com/navidrome/navidrome/releases/tag/v0.60.0