• caglararli@hotmail.com
  • 05386281520

CVE-2025-27112 | Navidrome up to 0.54.4 Subsonic API Endpoint improper authentication (GHSA-c3p4-vm8f-386p)

Çağlar Arlı      -    1 Views

CVE-2025-27112 | Navidrome up to 0.54.4 Subsonic API Endpoint improper authentication (GHSA-c3p4-vm8f-386p)

A vulnerability was found in Navidrome up to 0.54.4 and classified as critical. This issue affects some unknown processing of the component Subsonic API Endpoint. The manipulation leads to improper authentication. The identification of this vulnerability is CVE-2025-27112. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected component.