github.com
https://github.com/navidrome/navidrome CVE-2025-48948
HIGH
Navidrome Transcoding Permission Bypass Vulnerability Report
Record summary
CVE-2025-48948 has a selected CVSS score of 7.4 (high).
Description
Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user to bypass authorization checks and perform administrator-only transcoding configuration operations, including creating, modifying, and deleting transcoding settings. In the threat model where administrators are trusted but regular users are not, this vulnerability represents a significant security risk when transcoding is enabled. Version 0.56.0 patches the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
navidromeBrowse navidrome / navidrome | CVE List | < 0.56.0 | affected |
github.com/navidrome/navidromeBrowse Go / github.com/navidrome/navidrome | GitHub Advisory | Before 0.56.0 · Fixed in 0.56.0 | affected |
References
5github.com
https://github.com/navidrome/navidrome/commit/e5438552c63fecb6284e1b179dddae91ede869c8 github.com
https://github.com/navidrome/navidrome/pull/4096 github.comConfirmation
https://github.com/navidrome/navidrome/security/advisories/GHSA-f238-rggp-82m3 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-48948