CVE-2026-49130
MEDIUM EPSS 17.3%
Published May 28, 20261mo ago · Modified Jun 17, 20261w ago
6.9 CVSS 4.0
Published May 28, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago
Description
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject forged key-value lines through the location field into MPD protocol responses including playlistinfo, currentsong, and listplaylist outputs, as well as the state file writer, by exploiting Expat's decoding of numeric character references prior to the character data callback.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
17.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-93
References 7
- github.com https://github.com/MusicPlayerDaemon/MPD/commit/855085b35c67dddeef0652e2cb3ac8cdd4f457b7
- github.com https://github.com/MusicPlayerDaemon/MPD/issues/2483
- github.com https://github.com/MusicPlayerDaemon/MPD/releases/tag/v0.24.11
- mstreet97.github.io https://mstreet97.github.io/security-research/opensource/vulnerability-disclosure/cybersecurity/cve/2026/05/25/Four_Bugs_Reachable_nc.html
- raw.githubusercontent.com https://raw.githubusercontent.com/MusicPlayerDaemon/MPD/v0.24.11/NEWS
- musicpd.org https://www.musicpd.org/news/2026/05/mpd-0-24-11-released/
- vulncheck.com https://www.vulncheck.com/advisories/music-player-daemon-crlf-injection-via-xspfplaylistplugin-cxx
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.