Vulnerability Description
Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and HasAudioContentType checks used by the regular radio API. app/Http/Requests/Subsonic/CreateInternetRadioStationRequest.php and app/Http/Requests/Subsonic/UpdateInternetRadioStationRequest.php pass the stored URL through app/Services/RadioService.php to app/Services/Radio/RadioStreamProxy.php, where RadioStreamProxy::openStream() calls fopen($url, 'r', false, $context). Streaming /radio/stream/{id} returns the upstream response body, allowing access to loopback, RFC1918, Docker bridge, metadata, or other internal HTTP services reachable from the Koel server. This issue is fixed in version 9.7.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/koel/koel/commit/1331f335342b405e60ffabdd60f1f398508f996f
- https://github.com/koel/koel/pull/2545
- https://github.com/koel/koel/releases/tag/v9.7.0
- https://github.com/koel/koel/security/advisories/GHSA-6p96-cfg5-4vhp
- https://github.com/koel/koel/security/advisories/GHSA-6p96-cfg5-4vhp
FAQ
What is CVE-2026-54493?
CVE-2026-54493 is a vulnerability with a CVSS score of 7.7 (HIGH). Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's ...
How severe is CVE-2026-54493?
CVE-2026-54493 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54493?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.