CVE-2026-44482
CRITICALsoundcloud-rpc: Remote Code Execution via XSS in Track Title
Title source: cnaDescription
soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the user's machine. The application exposes a preload API (window.soundcloudAPI.sendTrackUpdate) to the remote SoundCloud page. Track metadata from SoundCloud is trusted and forwarded through IPC into the Electron main process. The app later renders that metadata as raw HTML inside privileged Electron views that have Node.js integration enabled. This vulnerability is fixed in 0.1.8.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/richardhbtz/soundcloud-rpc/security/advisories/GHSA-p37x-32p8-445f
Scores
CVSS v3
9.6
EPSS
0.0034
EPSS Percentile
25.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
CWE-79
CWE-862
CWE-94
Status
published
Products (1)
richardhbtz/soundcloud-rpc
< 0.1.8
Published
May 14, 2026
Tracked Since
May 14, 2026