Executive brief
Koel, a personal music streaming server, is vulnerable to a security flaw where an authenticated user can force the server to make unauthorized requests to internal network services. By providing a malicious podcast feed URL, an attacker could probe internal systems or access data that is not intended to be public. This could lead to the exposure of sensitive internal information or allow an attacker to interact with other services running on the same network as the music server.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Koel's Subsonic 'createPodcastChannel.view' endpoint and the 'PodcastService::getStreamableUrl()' method. The Subsonic endpoint fails to apply safe URL checks to user-supplied podcast feed URLs before fetching them server-side. Additionally, the stream helper validates only the initial URL but fails to re-validate subsequent redirect targets followed by the Guzzle HTTP client. An authenticated attacker with a valid Subsonic API key can exploit these gaps to perform blind SSRF against loopback or internal HTTP endpoints. Depending on the response format of the internal service, data may be reflected back to the attacker. The issue is fixed in version 9.7.0.
Affected products
- phanan Koel <= 9.6.0
Timeline
- 2026-06-04: disclosed
- 2026-06-04: patched: Version 9.7.0 released
- 2026-07-15: advisory