PT-2024-29336 · Navidrome · Navidrome

Yuexi Zhang

·

Published

2024-08-01

·

Updated

2025-08-26

·

CVE-2024-41259

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Navidrome version 0.52.3
Description The issue concerns the use of an insecure hashing algorithm, specifically MD5, in the Gravatar service of Navidrome. This allows attackers to manipulate a user's account information.
Recommendations For Navidrome version 0.52.3, consider disabling the use of the MD5 hashing algorithm in the Gravatar service until a secure alternative is implemented. Restrict access to account information to minimize the risk of exploitation.

Fix

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-41259
GHSA-HRMX-8JJV-G758
GO-2024-3029

Affected Products

Navidrome