PT-2025-46920 · Sonarr · Sonarr
Lakshay12311
·
Published
2025-11-13
·
Updated
2025-11-14
·
CVE-2025-13131
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sonarr version 4.0.15.2940
Description
A security issue exists in Sonarr that involves incorrect default permissions. The issue is related to an unknown function within the file
C:ProgramDataSonarrbinSonarr.Console.exe of the Service component. Exploitation requires local access. The vendor classifies this as a low severity issue because exploitation would require either changing the service to a highly privileged account or an attacker possessing administrative privileges.Recommendations
Update to Sonarr version 5 or later.
Exploit
Fix
Incorrect Default Permissions
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sonarr