Executive brief
Music Player Daemon (MPD) is a service used to manage and play music across a network. A security flaw allows unauthenticated attackers to trick the server into making unauthorized requests to internal or restricted network services. This could lead to the exposure of sensitive internal information or allow an attacker to interact with other services on the local network that are not intended to be public.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the CurlInputPlugin of Music Player Daemon (MPD) because it sets CURLOPT_FOLLOWLOCATION without restricting the allowed redirect protocols via CURLOPT_REDIR_PROTOCOLS_STR. On systems using libcurl versions prior to 7.85.0, this allows an unauthenticated attacker to provide a malicious HTTP URL that redirects the daemon to non-HTTP protocols such as gopher, ftp, sftp, ldap, or dict. Attackers can trigger this via commands like 'add', 'readcomments', 'albumart', 'readpicture', or 'load'. This can be used to probe internal network services or leak service banners. The issue is addressed in MPD 0.24.11 by requiring libcurl 7.85.0 or later, which defaults to a safer set of redirect protocols.
Affected products
- Music Player Daemon Music Player Daemon (MPD) before 0.24.11
Timeline
- 2026-05-14: disclosed: Issue reported on GitHub
- 2026-05-15: patched: Version 0.24.11 released
- 2026-05-28: advisory: CVE-2026-49129 published
References
- https://github.com/MusicPlayerDaemon/MPD/commit/78341dd6c7b101c3feede233d4cc4f8f1fcc4bb3
- https://github.com/MusicPlayerDaemon/MPD/issues/2487
- https://github.com/MusicPlayerDaemon/MPD/releases/tag/v0.24.11
- https://raw.githubusercontent.com/MusicPlayerDaemon/MPD/v0.24.11/NEWS
- https://www.musicpd.org/news/2026/05/mpd-0-24-11-released/
- https://www.vulncheck.com/advisories/music-player-daemon-ssrf-via-curlinputplugin