{"id":"CVE-2025-48948","aliases":["GHSA-f238-rggp-82m3","GO-2025-3733"],"url":"https://o3.security/vulnerability/CVE-2025-48948","summary":"Navidrome Transcoding Permission Bypass Vulnerability Report","details":"Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user to bypass authorization checks and perform administrator-only transcoding configuration operations, including creating, modifying, and deleting transcoding settings. In the threat model where administrators are trusted but regular users are not, this vulnerability represents a significant security risk when transcoding is enabled. Version 0.56.0 patches the issue.","published":"2025-05-30T19:25:41.422Z","modified":"2026-08-12T03:51:20.796270801Z","cvss":null,"epss":{"score":0.00451,"percentile":0.37301,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/navidrome/navidrome","fixedVersion":"0.56.0"}],"fix":{"url":"https://github.com/navidrome/navidrome/commit/e5438552c63fecb6284e1b179dddae91ede869c8","label":"navidrome/navidrome@e543855"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48948.json"},{"type":"ADVISORY","url":"https://github.com/navidrome/navidrome/security/advisories/GHSA-f238-rggp-82m3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48948"},{"type":"FIX","url":"https://github.com/navidrome/navidrome/commit/e5438552c63fecb6284e1b179dddae91ede869c8"},{"type":"FIX","url":"https://github.com/navidrome/navidrome/pull/4096"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.796270801Z"}}