blob: fb94c7fb0bf4f6fa76a8ff2a758b10d5d35de071 [file] [log] [blame]
id: GO-2025-3734
modules:
- module: github.com/navidrome/navidrome
versions:
- introduced: 0.55.0
- fixed: 0.56.0
vulnerable_at: 0.55.2
summary: Navidrome allows SQL Injection via role parameter in github.com/navidrome/navidrome
cves:
- CVE-2025-48949
ghsas:
- GHSA-5wgp-vjxm-3x2r
references:
- advisory: https://github.com/navidrome/navidrome/security/advisories/GHSA-5wgp-vjxm-3x2r
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-48949
- fix: https://github.com/navidrome/navidrome/commit/b19d5f0d3e079639904cac95735228f445c798b6
source:
id: GHSA-5wgp-vjxm-3x2r
created: 2025-06-03T13:21:08.443051-04:00
review_status: UNREVIEWED