CVE-2025-48949 | Navidrome up to 0.55.2 API Endpoint /api/artist role sql injection (GHSA-5wgp-vjxm-3x2r)
A vulnerability was found in Navidrome up to 0.55.2. It has been declared as critical. This vulnerability affects unknown code of the file /api/artist of the component API Endpoint. The manipulation of the argument role leads to sql injection.
This vulnerability was named CVE-2025-48949. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.