Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alexgustafsson

#43208de 53,632
6.1CVSS total
Vulnerabilidades · 1
PT-2026-6325
6.1
2026-02-04
Navidrome · Navidrome · CVE-2026-25578
**Name of the Vulnerable Software and Affected Versions** Navidrome versions prior to 0.60.0 **Description** Navidrome is a web-based music collection server and streamer. A cross-site scripting issue exists in the frontend that allows a malicious attacker to inject code through the comment metadata of a song. This could potentially lead to the exfiltration of user credentials. The vulnerable component is the frontend application. The attack vector involves manipulating the `comment` metadata associated with a song. **Recommendations** Update to version 0.60.0 or later.