CVE-2026-50231
Description
Lyrion Music Server 9.2.0 has an unauthenticated stored XSS vulnerability in the log viewer, allowing script injection via template variables.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Lyrion Music Server 9.2.0 has an unauthenticated stored XSS vulnerability in the log viewer, allowing script injection via template variables.
Vulnerability
Lyrion Music Server version 9.2.0 contains an unauthenticated stored cross-site scripting (XSS) vulnerability within its log viewer. This flaw arises from unescaped template variables, allowing attackers to inject malicious scripts. The vulnerability is present in version 9.2.0 [2].
Exploitation
Attackers can inject XSS payloads by exploiting unescaped template variables within the log viewer. This can be achieved through the search, lines, and path query parameters. Alternatively, attackers can craft values that are logged, such as URLs, User-Agent headers, stream titles, or player names, to trigger the vulnerability [2].
Impact
Successful exploitation allows attackers to execute arbitrary scripts within the context of a user's browser. This can lead to various malicious actions, including session hijacking, data theft, or redirection to phishing sites, depending on the injected script [2].
Mitigation
Lyrion Music Server version 9.2.0 is affected. A patched version is available. Users are advised to update to a fixed version as soon as possible. Specific patch version and release date are not yet disclosed in the available references [2].
AI Insight generated on Jun 5, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: =9.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
0No linked articles in our index yet.