← Zurück zur CVE-Suche

CVE-2026-49130

Music Player Daemon (MPD)

Beschreibung

Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject forged key-value lines through the location field into MPD protocol responses including playlistinfo, currentsong, and listplaylist outputs, as well as the state file writer, by exploiting Expat-s decoding of numeric character references prior to the character data callback.

CVSS 5.3EPSS 0.26%Risiko 0.54
Quelle öffnen
Veröffentlicht
2026-05-28 20:16:26
Betroffene Versionen
<0.24.11
Typ
Package
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N