go.senan.xyz/gonic
Activity
- Latest release
- 3mo ago
- Total releases
- 55
- Cadence
- ~11 days
- Last 12 months
- 5
Details
- First release
- Nov 24, 2019
| Version | Released | |
|---|---|---|
v0.22.0
minor
|
v0.22.0
minor
Dependencies (34)
+ 26 more |
|
v0.21.0
minor
|
v0.21.0
minor
Dependencies (34)
+ 26 more |
|
v0.20.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.20.1
patch
Dependencies (32)
+ 24 more |
|
v0.20.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.20.0
minor
Dependencies (32)
+ 24 more |
|
v0.19.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.19.0
minor
Dependencies (32)
+ 24 more |
|
v0.18.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.18.0
minor
Dependencies (30)
+ 22 more |
|
v0.17.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (29)
+ 21 more |
|
v0.16.4
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.4
patch
Dependencies (28)
+ 20 more |
|
v0.16.3
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.3
patch
Dependencies (28)
+ 20 more |
|
v0.16.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.2
patch
Dependencies (28)
+ 20 more |
|
v0.16.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.1
patch
Dependencies (28)
+ 20 more |
|
v0.16.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (28)
+ 20 more |
|
v0.16.0-rc1
pre
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.16.0-rc1
pre
Dependencies (31)
+ 23 more |
|
v0.15.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.15.2
patch
Dependencies (26)
+ 18 more |
|
v0.15.1
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.15.1
minor
Dependencies (26)
+ 18 more |
|
v0.15.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.15.0
minor
Dependencies (24)
+ 16 more |
|
v0.14.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.14.0
minor
Dependencies (19)
+ 11 more |
|
v0.13.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.13.1
patch
Dependencies (19)
+ 11 more |
|
v0.13.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (19)
+ 11 more |
|
v0.12.3
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.12.3
patch
Dependencies (19)
+ 11 more |
|
v0.12.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.12.2
patch
Dependencies (19)
+ 11 more |
|
v0.12.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.12.1
patch
Dependencies (19)
+ 11 more |
|
v0.12.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.12.0
minor
Dependencies (19)
+ 11 more |
|
v0.11.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.11.1
patch
Dependencies (18)
+ 10 more |
|
v0.11.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.11.0
minor
Dependencies (18)
+ 10 more |
|
v0.10.3
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.3
patch
Dependencies (17)
+ 9 more |
|
v0.10.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.2
patch
Dependencies (17)
+ 9 more |
|
v0.10.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.1
patch
Dependencies (17)
+ 9 more |
|
v0.10.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.10.0
minor
Dependencies (17)
+ 9 more |
|
v0.9.6
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.6
patch
Dependencies (17)
+ 9 more |
|
v0.9.5
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.5
patch
Dependencies (17)
+ 9 more |
|
v0.9.4
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.4
patch
Dependencies (17)
+ 9 more |
|
v0.9.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.1
patch
Dependencies (17)
+ 9 more |
|
v0.9.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.9.0
minor
Dependencies (17)
+ 9 more |
|
v0.8.7
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.7
patch
Dependencies (19)
+ 11 more |
|
v0.8.6
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.6
patch
Dependencies (19)
+ 11 more |
|
v0.8.5
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.5
patch
Dependencies (16)
+ 8 more |
|
v0.8.4
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.4
patch
Dependencies (16)
+ 8 more |
|
v0.8.3
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.3
patch
Dependencies (16)
+ 8 more |
|
v0.8.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.2
patch
Dependencies (16)
+ 8 more |
|
v0.8.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.8.0
minor
Dependencies (16)
+ 8 more |
|
v0.7.4
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.4
patch
Dependencies (15)
+ 7 more |
|
v0.7.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.2
patch
Dependencies (15)
+ 7 more |
|
v0.7.1
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.7.1
minor
Dependencies (15)
+ 7 more |
|
v0.6.3
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.6.3
patch
Dependencies (14)
+ 6 more |
|
v0.6.2
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.6.2
patch
Dependencies (14)
+ 6 more |
|
v0.6.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (14)
+ 6 more |
|
v0.5.1
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.5.1
patch
Dependencies (14)
+ 6 more |
|
v0.5.0
minor
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (14)
+ 6 more |
|
v0.4.3
patch
3 CVEs
CVE-2026-49338
GO-2026-5830
GHSA-hmgp-w9jm-vp95
Jul 07, 2026
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR) in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49340
GO-2026-5827
GHSA-4gxv-p5g5-j7w7
Jul 07, 2026
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host in go.senan.xyz/gonic Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49339
GO-2026-5825
GHSA-2fp4-5v5c-4448
Jul 07, 2026
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists in go.senan.xyz/gonic gonic: Path Traversal in playlist Fixed in
0.21.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.4.3
patch
Dependencies (14)
+ 6 more |