Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23877

Опубликовано: 19 янв. 2026
Источник: nvd
EPSS Низкий

Описание

Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's list_folders() function in the /folder/dir-browser endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem. Version 2.1.4 fixes the issue.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-25

Связанные уязвимости

github
17 дней назад

Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-25