OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions through the query= and filter= parameters. The vulnerability stems from insufficient sanitization of parameters used for integer-mapped DAAP fields, enabling attackers to bypass filters and gain unauthorized access to media library data. The attack requires network access to the vulnerable DAAP service and appears to have low complexity, as it exploits straightforward parameter injection. The primary impact is confidentiality compromise, allowing unauthorized disclosure of media library information. The FAUCET Risk Score of 46.0/100 indicates moderate risk, though the EPSS score of 0.00036 suggests relatively low exploitation probability across the threat landscape. There is currently no indication of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and it remains inactive on threat tracking hot lists. No publicly available exploit code has been confirmed, and community attention appears minimal at this time. Organizations running affected OwnTone Server versions should prioritize patching to versions 29.1 or later to mitigate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 28.4.0, < 29.1.0CPE match | cpe:2.3:a:owntone:owntone_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.