PT-2026-39464 · Unknown · Soundcloud-Rpc
Matheus-Hrm
·
Published
2026-05-10
·
Updated
2026-05-14
·
CVE-2026-44482
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
soundcloud-rpc versions prior to 0.1.8
Description
An issue exists where track titles containing HTML payloads can be executed locally within the Electron application. Attacker-controlled SoundCloud track metadata can lead to local command execution on the user's machine. The application exposes a preload API 'window.soundcloudAPI.sendTrackUpdate' to the remote SoundCloud page, and track metadata is trusted and forwarded through Inter-Process Communication (IPC) into the Electron main process. This metadata is subsequently rendered as raw HTML inside privileged Electron views that have Node.js integration enabled.
Recommendations
Update to version 0.1.8.
Exploit
Fix
RCE
Code Injection
Missing Authorization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Soundcloud-Rpc