We found results for “”
CVE-2026-23877
Good to know:
Date: January 19, 2026
Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's "list_folders()" function in the "/folder/dir-browser" endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem. Version 2.1.4 fixes the issue.
Severity Score
Related Resources (5)
Severity Score
Top Fix
Upgrade Version
Upgrade to version swingmusic - 2.1.4;https://github.com/swingmx/swingmusic.git - v2.1.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


