CVE-2026-25578
Unknown Unknown - Not Provided
Cross-Site Scripting in Navidrome Frontend Enables Credential Theft

Publication date: 2026-02-04

Last updated on: 2026-02-18

Assigner: GitHub, Inc.

Description
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials. This issue has been patched in version 0.60.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-04
Last Modified
2026-02-18
Generated
2026-06-16
AI Q&A
2026-02-05
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
navidrome navidrome to 0.60.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-80 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

To mitigate this vulnerability, you should upgrade Navidrome to version 0.60.0 or later, where the cross-site scripting issue has been patched.

Executive Summary

This vulnerability is a cross-site scripting (XSS) issue in Navidrome, an open source web-based music collection server and streamer. Before version 0.60.0, an attacker could inject malicious code through the comment metadata of a song in the frontend interface.

This injected code could then be used to steal user credentials by exfiltrating them from the affected system.

The vulnerability has been fixed in version 0.60.0.

Impact Analysis

This vulnerability can impact you by allowing an attacker to steal your user credentials through malicious code injected into song comment metadata.

If exploited, it could lead to unauthorized access to your Navidrome account or other systems where the same credentials are used.

Compliance Impact

I don't know

Detection Guidance

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart