CVE-2026-50234
Lyrion Music Server 9.2.0 Path Traversal File Read
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
LMS Community · Lyrion Music ServerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →