
CVE-2026-25578 Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the frontend allows a mal… https://www.cve.org/CVERecord?id=CVE-2026-25578
Post summary
The post announces CVE-2026-25578, a cross‑site scripting flaw in Navidrome versions before 0.60.0, but offers no further exploitation details or mitigation information.

