Impact
gonic versions before 0.22.0 do not validate administrator privileges on the Subsonic startScan endpoint, allowing any authenticated user to trigger rescans of the media library. This flaw enables attackers to repeatedly invoke the startScan API, forcing the server to perform CPU‑intensive and I/O‑heavy filesystem traversals that can overload the host and deny service to legitimate users. The weakness is a missing authorization check, classified as CWE‑862.
Affected Systems
All instances of the gonic media server running any release prior to v0.22.0 are vulnerable. The issue applies to all operating systems and deployment environments where the Subsonic API is enabled, as vendor sentriz builds the application with this vulnerable path.
Risk and Exploitability
The objective score of 5.3 indicates a moderate severity level. While the EPSS metric is not available, the vulnerability can be exploited by any authenticated user, which is a common scenario in multi‑user deployments. The flaw is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation at this time. However, the lack of an administrator guard permits denial‑of‑service conditions that could disrupt services for all users on the affected server.
OpenCVE Enrichment