The linkdave server does not enforce authentication on its REST and WebSocket routes in versions prior to 0.1.5.
An attacker with network access to the server port can:
/ws) and receive a valid session_id in the OpReady response./stats endpoint (still public after the fix).[1] If on >=0.1.0, attackers are restricted to creating, controlling and deleting players created within their own session ID.
The following routes were entirely unauthenticated in >= 0.0.1, < 0.1.5:
| Method | Path | Description |
|---|---|---|
POST |
/sessions/{session_id}/players/{guild_id}/play |
Start audio playback |
POST |
/sessions/{session_id}/players/{guild_id}/pause |
Pause playback |
POST |
/sessions/{session_id}/players/{guild_id}/resume |
Resume playback |
POST |
/sessions/{session_id}/players/{guild_id}/stop |
Stop playback |
POST |
/sessions/{session_id}/players/{guild_id}/seek |
Seek to position |
PATCH |
/sessions/{session_id}/players/{guild_id}/volume |
Set volume |
DELETE |
/sessions/{session_id}/players/{guild_id} |
Disconnect from voice channel |
GET |
/ws |
WebSocket event stream |
Update to 0.1.5.
- image: ghcr.io/shi-gg/linkdave:0.1.4
+ image: ghcr.io/shi-gg/linkdave:latest
or
docker pull ghcr.io/shi-gg/linkdave:latest
After upgrading, set the LINKDAVE_PASSWORD environment variable to a strong secret value. If this variable is left unset, the server will still accept all connections without authentication even on >= 0.1.5.
Server configuration (e.g. compose.yml):
environment:
LINKDAVE_PASSWORD: ${LINKDAVE_PASSWORD}
echo "LINKDAVE_PASSWORD=$(openssl rand -hex 16)" >> .env
To restart the stack, run
docker compose up -d
TypeScript client (0.1.5+):
The client automatically handles authentication. Pass the password when constructing the client:
const linkdave = new LinkDaveClient({
nodes: [
{
name: "main",
url: process.env.LINKDAVE_URI,
password: process.env.LINKDAVE_PASSWORD
}
]
});
If upgrading is not immediately possible, restrict network access to the server's port using a firewall so it is only accessible from trusted internal IP addresses.
{
"cwe_ids": [
"CWE-306"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-10T01:18:20Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}