← Voltar à pesquisa de CVEs

CVE-2026-49130

Music Player Daemon (MPD)

Descrição

Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject forged key-value lines through the location field into MPD protocol responses including playlistinfo, currentsong, and listplaylist outputs, as well as the state file writer, by exploiting Expat-s decoding of numeric character references prior to the character data callback.

CVSS 5.3EPSS 0.26%Risco 0.54
Ver fonte
Publicação
2026-05-28 20:16:26
Versões afetadas
<0.24.11
Tipo
Package
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N