CVE-2026-26975 is a critical remote code execution vulnerability affecting Music Assistant versions 2.6.3 and below, an open-source media library manager. Unauthenticated attackers on the same network can exploit a flaw in the music/playlists/update API to bypass file extension enforcement and write arbitrary files to the filesystem. This allows for the injection of malicious Python path (.pth) files into the site-packages directory, leading to arbitrary code execution due to the application running with root privileges. Rated 8.8 HIGH on CVSS, this vulnerability has a low attack complexity and can result in complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.0CPE matchmatch criteria | cpe:2.3:a:music-assistant:music_assistant_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.