PT-2026-3505 · Unknown · Swingmusic

·

CVE-2026-23877

·

Published

2026-01-19

·

Updated

2026-07-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Swing Music versions prior to 2.1.4
Description Swing Music is a self-hosted music player for local audio files. The list folders() function within the /folder/dir-browser API endpoint is susceptible to directory traversal attacks. Authenticated users, even those without administrative privileges, can potentially browse arbitrary directories on the server filesystem.
Recommendations Update to version 2.1.4 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23877
GHSA-PJ88-9XWW-GXMH
PYSEC-2026-1947

Affected Products

Swingmusic