Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-56362

19
FAUCET Score

CVE-2024-56362 affects Navidrome, an open-source music server, by storing the JWT secret in plaintext within its database file. This allows any attacker with local access to the database to retrieve the secret, posing a medium severity risk (CVSS 5.5) due to potential compromise of user authentication. While the vulnerability has a high confidentiality impact, it requires local access and has no known public exploits, Metasploit modules, or significant community discussion. A fix is available in Navidrome version 0.54.1.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.54.1CPE matchmatch criteria
cpe:2.3:a:navidrome:navidrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 31st percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/navidrome/navidromeFixed in: 0.54.1

Vendor Advisories (1)

goGHSA-xwx7-p63r-2rj8high

Navidrome Stores JWT Secret in Plaintext in navidrome.db

Dec 23, 2024

References

github.com / navidrome/navidrome/commit/7f030b0859653593fd2ac0df69f4a313f9caf9ff
Patch
github.com / navidrome/navidrome/commit/9cbdb20a318a49daf95888b1fd207d4d729b55f1
Patch
github.com / navidrome/navidrome/security/advisories/GHSA-xwx7-p63r-2rj8
Vendor Advisory