Release v0.54.5 · navidrome/navidrome · GitHub
Release v0.54.5 · navidrome/navidrome · GitHub
github.com
Release v0.54.5 · navidrome/navidrome
This is an important security fix. Please update ASAP. A proper CVE advisory will be published soon and will be linked here.
This seems quite serious, I'll definitely be reading the CVE once it's published. Luckily, I noticed the github notification of the release after only a couple of hours.
edit: I read the advisory and it wasn't too bad in terms of attacker access: