PT-2025-7778 · Navidrome+1 · Navidrome+1

Daniele-Athome

·

Published

2025-02-24

·

Updated

2025-03-13

·

CVE-2025-27112

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Navidrome versions 0.52.0 through 0.54.4
Description The issue is related to a flaw in the authentication check process in certain Subsonic API endpoints. This flaw allows an attacker to bypass authentication by specifying any arbitrary non-existent username along with a salted hash of an empty password, granting access to read-only data without valid credentials. The attacker can view various information, such as user playlists, but cannot modify data due to insufficient permissions.
Recommendations For Navidrome versions 0.52.0 through 0.54.4, update to version 0.54.5 to resolve the issue.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3437
CVE-2025-27112
GHSA-C3P4-VM8F-386P
GO-2025-3484
OPENSUSE-SU-2025:14889-1

Affected Products

Alt Linux
Navidrome