Executive brief
Lyrion Music Server, a platform used for managing and streaming digital music collections, contains a security flaw that allows unauthorized individuals to access files on the host system. By sending specially crafted requests to the server's web interface, an attacker can bypass security restrictions to read sensitive configuration files or system data. This could lead to the exposure of private information or credentials, potentially compromising the security of the entire device or network where the server is hosted.
Technical details
A path traversal vulnerability (CWE-22) exists in the web server component of Lyrion Music Server version 9.2.0 and below. The application fails to properly sanitize file path parameters, allowing an unauthenticated attacker to use 'dot-dot-slash' (../) sequences to navigate outside of the intended web root directory. By exploiting this, a remote attacker can access sensitive files on the host filesystem that the web server process has permissions to read. The vulnerability is reachable over the network without user interaction or prior authentication. As of the advisory date, users should ensure they are running the latest patched version or restrict network access to the management interface.
Affected products
- Lyrion Music Server <= 9.2.0
Timeline
- 2026-06-05: disclosed: Initial disclosure by Zero Science Lab and VulnCheck
- 2026-06-05: advisory: CVE-2026-50234 published