Executive brief
Navidrome allows SQL Injection via role parameter in github.com/navidrome/navidrome
Affected products
- Go github.com/navidrome/navidrome
Junglewise Threat Intelligence
CVE-2025-48949 · Severity: medium · CVSS 4 · Published 2025-06-03
Technologies: github.com/navidrome/navidrome (Go). Vendors: Go.
Navidrome allows SQL Injection via role parameter in github.com/navidrome/navidrome