Junglewise Threat Intelligence

CVE-2026-50232: Lyrion Music Server stored XSS via media metadata tags

CVE-2026-50232 · Severity: high · CVSS 7.2 · Published 2026-06-05

Technologies: Lyrion Music Server. Vendors: Lyrion.

Executive brief

Lyrion Music Server, a platform used for managing and streaming digital music collections, is vulnerable to a security flaw where malicious code can be hidden inside music file information. If a user adds a specially crafted music file to their library, an attacker could remotely execute scripts in the user's web browser when they view the track details. This could allow an attacker to gain unauthorized access to server management functions, change settings, or steal sensitive configuration data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Lyrion Music Server version 9.2.0 and below. The application fails to properly sanitize metadata tags such as GENRE, ARTIST, and ALBUM within media files before displaying them in the web management interface. An attacker can craft a malicious media file containing XSS payloads in these tags; when the server processes the file and a user views the track information or plays the file via the web UI, the script executes in the context of the user's session. This can lead to unauthorized access to management functions and disclosure of server settings. The attack requires the server to index a malicious file but does not necessarily require prior authentication if the server is configured to monitor public or shared folders.

Affected products

  • Lyrion Lyrion Music Server <= 9.2.0

Timeline

  • 2026-06-05: disclosed: Initial disclosure by Zero Science Lab and VulnCheck
  • 2026-06-05: advisory: CVE-2026-50232 published

References

Related threats