PT-2026-44495 · Unknown · Music Player Daemon

Daniele Berardinelli

+1

·

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-49128

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Music Player Daemon (MPD) versions prior to 0.24.11
Description A path traversal issue exists within the local storage plugin in the functions LocalStorage::MapFSOrThrow() and LocalStorage::MapUTF8(). The flaw occurs because the on-disk path is created by joining the storage root with a user-supplied URI as plain strings without canonicalization, allowing '..' segments to remain in the resolved path. An unauthenticated attacker can use the 'listfiles' command to enumerate names, sizes, and modification times of arbitrary directories readable by the MPD process, or the 'albumart' command to read image files in any directory outside the configured music directory.
Recommendations Update to version 0.24.11 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-49128

Affected Products

Music Player Daemon