PT-2026-39464 · Unknown · Soundcloud-Rpc

Matheus-Hrm

·

Published

2026-05-10

·

Updated

2026-05-14

·

CVE-2026-44482

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions soundcloud-rpc versions prior to 0.1.8
Description An issue exists where track titles containing HTML payloads can be executed locally within the Electron application. Attacker-controlled SoundCloud track metadata can lead to local command execution on the user's machine. The application exposes a preload API 'window.soundcloudAPI.sendTrackUpdate' to the remote SoundCloud page, and track metadata is trusted and forwarded through Inter-Process Communication (IPC) into the Electron main process. This metadata is subsequently rendered as raw HTML inside privileged Electron views that have Node.js integration enabled.
Recommendations Update to version 0.1.8.

Exploit

Fix

RCE

Code Injection

Missing Authorization

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-44482

Affected Products

Soundcloud-Rpc