Executive brief
Sonicverse is a self-hosted platform used for managing and broadcasting live radio streams. A security flaw in the dashboard allows an authorized operator to force the server to make unauthorized requests to internal or external systems. This could allow an attacker to access sensitive internal data, interact with private cloud infrastructure, or bypass network security controls, potentially leading to a full compromise of the hosting environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Sonicverse Radio Audio Streaming Stack dashboard within the API client (apps/dashboard/lib/api.ts). The application accepts user-controlled URLs and passes them directly to a server-side HTTP client without sufficient validation or sanitization. An authenticated operator can exploit this to pivot from the dashboard backend to reach internal services, cloud instance metadata endpoints, or other systems not exposed to the public internet. The vulnerability specifically affects deployments created via the provided install.sh script. A fix has been implemented in commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4 by introducing URL validation and host allow-listing.
Affected products
- Sonicverse Radio Audio Streaming Stack Installations created with install.sh before commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4
Timeline
- 2026-04-08: advisory: GitHub Security Advisory published by vendor
- 2026-04-09: disclosed: CVE-2026-40089 published
- 2026-04-09: patched: Fix identified in commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4