CVE-2026-48559

Source
https://cve.org/CVERecord?id=CVE-2026-48559
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48559.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48559
Published
2026-06-01T13:15:42Z
Modified
2026-08-12T03:51:20Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags
Details

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48559.json"
}
References

Affected packages

Git / github.com/epoupon/lms

Affected ranges

Type
GIT
Repo
https://github.com/epoupon/lms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.76.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.0.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v3.*
v3.0.0
v3.1.0
v3.10.0
v3.10.1
v3.11.0
v3.12.0
v3.12.1
v3.13.0
v3.14.0
v3.15.0
v3.15.1
v3.16.0
v3.17.0
v3.18.0
v3.19.0
v3.19.1
v3.19.2
v3.2.0
v3.20.0
v3.21.0
v3.21.1
v3.22.0
v3.23.0
v3.23.1
v3.24.0
v3.25.0
v3.25.1
v3.25.2
v3.26.0
v3.26.1
v3.27.0
v3.28.0
v3.29.0
v3.29.1
v3.3.0
v3.30.0
v3.30.1
v3.31.0
v3.31.1
v3.31.2
v3.32.0
v3.33.0
v3.34.0
v3.35.0
v3.35.1
v3.36.0
v3.37.0
v3.38.0
v3.39.0
v3.4.0
v3.40.0
v3.40.1
v3.41.0
v3.42.0
v3.42.1
v3.43.0
v3.44.0
v3.44.1
v3.45.0
v3.45.1
v3.45.2
v3.46.0
v3.46.1
v3.47.0
v3.48.0
v3.49.0
v3.5.0
v3.50.1
v3.51.0
v3.51.1
v3.52.0
v3.53.0
v3.53.1
v3.54.0
v3.55.0
v3.56.0
v3.57.0
v3.58.0
v3.59.0
v3.59.1
v3.6.0
v3.6.1
v3.6.2
v3.6.3
v3.60.0
v3.60.1
v3.61.0
v3.62.0
v3.62.1
v3.63.0
v3.64.0
v3.65.0
v3.66.0
v3.66.1
v3.67.0
v3.68.0
v3.68.1
v3.69.0
v3.7.0
v3.70.0
v3.71.0
v3.72.0
v3.72.1
v3.73.0
v3.74.0
v3.75.0
v3.76.0
v3.8.0
v3.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48559.json"