PT-2026-45437 · Unknown · Lightweight Music Server

Zeroscience

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-48559

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lightweight Music Server versions prior to 3.76.1
Description A stored cross-site scripting issue exists where attackers can execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags, specifically GENRE, ARTIST, or ALBUM. The payload is saved during library scanning and executed automatically in the web interface because the tag content is rendered using the Wt::TextFormat::UnsafeXHTML format in the src/lms/ui/Utils.cpp file without proper sanitization.
Recommendations Update to a version later than 3.76.0.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-48559

Affected Products

Lightweight Music Server