Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem. | |
| Title | Lyrion Music Server 9.2.0 Arbitrary Directory Listing | |
| Weaknesses | CWE-548 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-05T13:24:27.797Z
Reserved: 2026-06-04T10:47:01.275Z
Link: CVE-2026-50233
No data.
Status : Received
Published: 2026-06-05T14:16:36.550
Modified: 2026-06-05T14:16:36.550
Link: CVE-2026-50233
No data.
OpenCVE Enrichment
No data.