Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alexgustafsson

#43978of 53,630
6.1Total CVSS
Vulnerabilities · 1
PT-2026-6325
6.1
2026-02-04
Navidrome · Navidrome · CVE-2026-25578
**Name of the Vulnerable Software and Affected Versions** Navidrome versions prior to 0.60.0 **Description** Navidrome is a web-based music collection server and streamer. A cross-site scripting issue exists in the frontend that allows a malicious attacker to inject code through the comment metadata of a song. This could potentially lead to the exfiltration of user credentials. The vulnerable component is the frontend application. The attack vector involves manipulating the `comment` metadata associated with a song. **Recommendations** Update to version 0.60.0 or later.