CVE-2023-36177

Name
CVE-2023-36177
Description
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org http://snapcast.com
cve@mitre.org https://oxnan.com/posts/Snapcast_jsonrpc_rce
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/07/msg00015.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
snapcast 3.19-community 0.27.0-r4 Bart Ribbers <bribbers@disroot.org> possibly vulnerable