Description
Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5992.php
www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5992.php (Zero Science Lab Disclosure)
www.vulncheck.com/...n-music-server-path-traversal-file-read (VulnCheck Advisory: Lyrion Music Server 9.2.0 Path Traversal File Read)