CVE-2025-48948

Name
CVE-2025-48948
Description
Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user to bypass authorization checks and perform administrator-only transcoding configuration operations, including creating, modifying, and deleting transcoding settings. In the threat model where administrators are trusted but regular users are not, this vulnerability represents a significant security risk when transcoding is enabled. Version 0.56.0 patches the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/navidrome/navidrome/commit/e5438552c63fecb6284e1b179dddae91ede869c8
MISC https://github.com/navidrome/navidrome/pull/4096
CONFIRM https://github.com/navidrome/navidrome/security/advisories/GHSA-f238-rggp-82m3

Match rules

CPE URI Source package Min version Max version
navidrome >= 0 < 0.56.0
cpe:2.3:a:navidrome:navidrome:*:*:*:*:*:*:*:* navidrome >= None < 0.56.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
navidrome edge-community 0.56.1-r0 Tom Lebreux <me@tomlebreux.com> fixed
navidrome edge-community 0.55.2-r1 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.55.2-r0 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.54.5-r2 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.54.5-r1 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.54.5-r0 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.54.4-r2 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.54.4-r1 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.54.4-r0 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.53.3-r1 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome edge-community 0.53.3-r0 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome 3.22-community 0.55.2-r4 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome 3.22-community 0.55.2-r3 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome 3.22-community 0.55.2-r2 Tom Lebreux <me@tomlebreux.com> possibly vulnerable
navidrome 3.22-community 0.53.3-r5 Tom Lebreux <me@tomlebreux.com> possibly vulnerable