
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23877 is a directory traversal vulnerability in Swing Music, a self-hosted music player for local audio files. The flaw exists in the list_folders() function exposed via the /folder/dir-browser endpoint, allowing any authenticated user — including non-admin accounts — to browse arbitrary directories on the server filesystem. All versions prior to 2.1.4 are affected. The vulnerability was disclosed on January 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, Feedly).
The root cause is classified as CWE-25 (Path Traversal: /../filedir) and CWE-284 (Improper Access Control). The @api.post("/dir-browser") endpoint in src/swingmusic/api/folder.py lacked both proper authorization enforcement and path canonicalization: it attempted to prepend / to non-existent paths, but this did not prevent traversal sequences such as /music/../proc/self/ from resolving outside the intended music directory. No admin privilege check was applied to the endpoint prior to the fix. The patch (commit 9a915ca) resolves paths using pathlib.Path.resolve(), validates them against configured root directories, and adds an @admin_required() decorator to the list_folders() function (Github Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to enumerate arbitrary directories on the server filesystem, bypassing the intended restriction to music library paths. This can expose sensitive information including configuration file locations, system file paths, user account names from directory listings, installed software versions, and log file locations. While integrity and availability are not directly impacted, the information gathered can serve as reconnaissance for follow-on attacks such as local file inclusion (LFI) or remote code execution (RCE) (Github Advisory).
A public proof-of-concept is included in the official security advisory, demonstrating exploitation via a simple curl command with a crafted JSON body containing a traversal path. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.073% (22nd percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).
access_token_cookie from the session./folder/dir-browser with a path containing ../ sequences to escape the music root directory:POST /folder/dir-browser HTTP/1.1
Host: <TARGET_IP>:1970
Content-Type: application/json
Cookie: access_token_cookie=<non-admin-token>
{"folder":"/music/../proc/self/", "tracks_only":false}--path-as-is flag to prevent the client from normalizing the traversal path:curl --path-as-is -i -s -k -X POST -H 'Content-Type: application/json' \
-b 'access_token_cookie=<token>' \
--data-binary '{"folder":"/music/../proc/self/", "tracks_only":false}' \
http://<TARGET_IP>:1970/folder/dir-browser/proc/self/fd, /proc/self/net) and iterate with different traversal paths to map sensitive directories such as /etc, /home, or application configuration paths (Github Advisory)./folder/dir-browser from authenticated sessions, particularly containing path components such as ../, /proc/, /etc/, or other non-music directories in the request body./folder/dir-browser with JSON bodies referencing paths outside configured root music directories; HTTP 200 responses to such requests on unpatched versions.folder parameter resolves to system paths (e.g., /proc/self, /etc, /home) rather than music library paths.Upgrade Swing Music to version 2.1.4 or later, which resolves the vulnerability by adding path canonicalization via pathlib.Path.resolve(), validating paths against configured root directories, and restricting the /folder/dir-browser endpoint to admin users only. As an interim workaround, restrict network access to the Swing Music application to trusted users and networks only, and audit user accounts to minimize the number of authenticated users. Review access logs for suspicious directory browsing activity targeting the /folder/dir-browser endpoint (Github Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."