← Volver al buscador de CVEs

CVE-2026-49130

Music Player Daemon (MPD)

Descripción

Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject forged key-value lines through the location field into MPD protocol responses including playlistinfo, currentsong, and listplaylist outputs, as well as the state file writer, by exploiting Expat-s decoding of numeric character references prior to the character data callback.

CVSS 5.3EPSS 0.26%Riesgo 0.54
Ver fuente
Publicación
2026-05-28 20:16:26
Versiones afectadas
<0.24.11
Tipo
Package
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N