High severity8.8NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026
CVE-2026-26975
CVE-2026-26975
Description
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API allows users to bypass the .m3u extension enforcement and write files anywhere on the filesystem, which is exacerbated by the container running as root. This can be exploited to achieve Remote Code Execution by writing a malicious .pth file to the Python site-packages directory, which will execute arbitrary commands when Python loads. This issue has been fixed in version 2.7.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <=2.6.3
- Range: <=2.6.3
- music-assistant/serverv5Range: < 2.7.0
- cpe:2.3:a:music-assistant:music_assistant_server:*:*:*:*:*:*:*:*Range: <2.7.0
Patches
Vulnerability mechanics
References
3- github.com/music-assistant/server/security/advisories/GHSA-7jcc-p6xr-835jnvdExploitVendor Advisory
- github.com/music-assistant/server/pull/2684nvdIssue Tracking
- github.com/music-assistant/server/releases/tag/2.7.0nvdRelease Notes
News mentions
1- ZDI-26-133: (Pwn2Own) Music Assistant _update_library_item External Control of File Path Remote Code Execution VulnerabilityZero Day Initiative · Mar 3, 2026