CVE-2026-23877
Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem. Version 2.1.4 fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.53%
- CWE
- CWE-25, CWE-284
- Published
- 2026-01-19
- Last modified
- 2026-03-12
Affected products
- swingmx swingmusic
Weakness type
Related vulnerabilities
- CVE-2026-68959 — SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
- CVE-2025-68916 — Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory...
- CVE-2025-58286 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this...
- CVE-2025-0225 — Tsinghua Unigroup Electronic Archives System exampleDownload.html path traversal
- CVE-2023-6947 — Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
- CVE-2024-2442 — Path Traversal vulnerability in Franklin Fueling System EVO 550/5000
- CVE-2023-52138 — Path traversal via crafted cpio archives in Engrampa archivers
- CVE-2023-6919 — Path Traversal in VGuard IP Camera Network Recorder