Impact
Podgrab exposes a missing authentication flaw where the /ws WebSocket endpoint is attached to the root router instead of the BasicAuth‑protected group. Unauthenticated clients can connect even if a password is set, listen to PlayerExists broadcasts that expose client‑supplied player identifiers, and replay these identifiers in RegisterPlayer messages to hijack queue payloads intended for authenticated users. The attacker thereby gains access to episode IDs, titles, server‑side file paths, and can interfere with legitimate playback.
Affected Systems
AkIlrex Podgrab is affected. No specific affected version information is available; any unpatched Podgrab instance exposing the /ws endpoint is at risk.
Risk and Exploitability
The CVSS score of 6.3 rates this as a medium‑severity vulnerability. The EPSS score is not available, indicating that exploitation likelihood information is incomplete, but the flaw permits straightforward network‑based attacks from any host that can reach the WebSocket endpoint. Because Podgrab frequently runs behind publicly reachable services, attackers can easily exploit the authentication bypass to obtain sensitive metadata and disrupt service for legitimate users. Although this vulnerability is not listed in the CISA KEV catalog, its impact remains significant for exposed installations.
OpenCVE Enrichment