CVE-2026-25578
EUVD-2026-532304.02.2026, 22:16
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials. This issue has been patched in version 0.60.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| navidrome | navidrome | 𝑥 < 0.60.0 |
𝑥
= Vulnerable software versions