๐Ÿ” CVE Alert

CVE-2026-104058

MEDIUM 5.3

Podgrab Missing Authentication on WebSocket /ws Endpoint

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.

CWE CWE-306
Vendor akhilrex
Product podgrab
Published Oct 1, 2026
Last Updated Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for akhilrex podgrab

Be the first to know when new medium vulnerabilities affecting akhilrex podgrab are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

akhilrex / podgrab
0 โ‰ค 032248091294dbf5b6a439a5afd93788a7cc647f

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/mansurmavlankulov/022bc672583687ccb34dcf4cb31b6188 vulncheck.com: https://www.vulncheck.com/advisories/podgrab-missing-authentication-on-websocket-ws-endpoint

Credits

Mansur Mavlankulov