CVE-2026-40089Disclosure(sonicverse / radio_audio_streaming_stack)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch sonicverse radio_audio_streaming_stack systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner bash <(curl -fsSL https://sonicverse.short.gy/install-audiostack)) are affected. In these deployments, the dashboard accepts user-controlled URLs and passes them directly to a server-side HTTP client without sufficient validation. An authenticated operator can abuse this to make arbitrary HTTP requests from the dashboard backend to internal or external systems. This vulnerability is fixed with commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • radio_audio_streaming_stack

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
radio_audio_streaming_stack

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-19: 104-0904-1004-19
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-101
General1
2026-04-191
Patch1
Full discourse5 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40089 | CVSS 9.9 🔴 CVE-2026-5997 | CVSS 9.8 🔴 CVE-2026-5996 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑CVSS CVEs without additional context such as PoC, exploitation status, or patches.

    0001062
    5.6K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2026-40089 (CVSS 9.9) Sonicverse Radio Stack SSRF allows authenticated operators to make arbitrary HTTP requests from dashboard backend to internal/external systems. Affected: Installs via install[.]sh script Patch: commit cb1ddba #CVE #Vulnerability #PatchNow https://t.co/IwaEnzM8va

    Post summary

    CVE‑2026‑40089 is an SSRF flaw in Sonicverse Radio Stack that has been patched with commit cb1ddba; no PoC or active exploitation details are mentioned.

    0000067
    26 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-40089: CRITICAL] Beware of Sonicverse Radio Audio Streaming Stack's SSRF vulnerability in API client, allowing unauthorized HTTP requests to internal/external systems. Update to fix commit cb1ddbac...#cve,CVE-2026-40089,#cybersecurity https://cvefind.com/CVE-2026-40089

    Post summary

    The post announces a critical SSRF flaw in Sonicverse Radio Audio Streaming Stack and recommends applying a patch commit to remediate the issue.

    0000039
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40089 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery… https://www.cve.org/CVERecord?id=CVE-2026-40089

    Post summary

    The post announces that Sonicverse’s dashboard contains an SSRF vulnerability (CVE‑2026‑40089), but provides no PoC, exploit, active‑use, or patch details.

    00000100
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40089: Sonicverse has Server-Side Reque... SSRF in Sonicverse's dashboard API lets authenticated users pivot through the radio stack's backend to hit internal ser... https://zerodaysignal.com/vulnerability/CVE-2026-40089 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑40089, a SSRF flaw in Sonicverse’s dashboard API that lets authenticated users reach internal services. It provides vulnerability details but no evidence of active exploitation, PoC code, or patches.

    0000042
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonicverseradio_audio_streaming_stack---

Explore more