CVE-2024-28194 affects YourSpotify versions prior to 1.8.0, where a hardcoded JWT secret allows attackers to forge authentication tokens. This critical vulnerability (CVSS 9.8) enables complete authentication bypass, granting unauthorized access to arbitrary user accounts, including administrative ones, with high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, the ease of exploitation (network attack, low complexity) makes it a significant risk. Users are strongly advised to upgrade to version 1.8.0 immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.0CPE matchmatch criteria | cpe:2.3:a:yooooomi:your_spotify:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.