Security: navidrome/navidrome
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
SQL Injection via role parameterGHSA-5wgp-vjxm-3x2r published
May 29, 2025 by deluanCritical -
Navidrome Transcoding Permission Bypass Vulnerability ReportGHSA-f238-rggp-82m3 published
May 29, 2025 by deluanCritical -
Authentication bypass in Subsonic API with non-existent usernameGHSA-c3p4-vm8f-386p published
Feb 22, 2025 by deluanModerate -
Plaintext Storage of JWT Secret in navidrome.dbGHSA-xwx7-p63r-2rj8 published
Dec 23, 2024 by deluanHigh -
Multiple SQL Injections and ORM LeakGHSA-58vj-cv5w-v4v6 published
Sep 20, 2024 by deluanCritical -
Parameter Tampering vulnerabilityGHSA-4jrx-5w4h-3gpm published
Apr 27, 2024 by deluanHigh -
Authentication bypass vulnerability in navidrome's subsonic endpointGHSA-wq59-4q6r-635r published
Dec 19, 2023 by deluanHigh
Learn more about advisories related to navidrome/navidrome in the GitHub Advisory Database