{"id":"CVE-2025-48949","aliases":["GHSA-5wgp-vjxm-3x2r","GO-2025-3734"],"url":"https://o3.security/vulnerability/CVE-2025-48949","summary":"Navidrome allows SQL Injection via role parameter","details":"Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the `role` parameter within the API endpoint `/api/artist`. Attackers can exploit this flaw to inject arbitrary SQL queries, potentially gaining unauthorized access to the backend database and compromising sensitive user information. Version 0.56.0 contains a patch for the issue.","published":"2025-05-30T19:40:51.355Z","modified":"2026-07-15T01:49:08.015362903Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/navidrome/navidrome","fixedVersion":"0.56.0"}],"fix":{"url":"https://github.com/navidrome/navidrome/commit/b19d5f0d3e079639904cac95735228f445c798b6","label":"navidrome/navidrome@b19d5f0"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48949.json"},{"type":"ADVISORY","url":"https://github.com/navidrome/navidrome/security/advisories/GHSA-5wgp-vjxm-3x2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48949"},{"type":"FIX","url":"https://github.com/navidrome/navidrome/commit/b19d5f0d3e079639904cac95735228f445c798b6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:08.015362903Z"}}