CVE-2026-54491High· 7.1▾ TwilightKoel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without pinning the validated address, and most…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
0.2% → 0.3%
Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without pinning the validated address, and most paths lack redirect-hop validation and do not revalidate every redirect target. PhanAn\Poddle\Poddle::fromUrl(), PodcastService::getStreamableUrl(), PodcastService::isPodcastObsolete(), App\Rules\HasAudioContentType, and App\Rules\SafeUrl can therefore follow an attacker-controlled redirect to an internal address or connect after DNS rebinding changes a public resolution to a private one. These paths are reachable through podcast and radio APIs, including createPodcastChannel, createInternetRadioStation, refreshPodcasts, apiResource podcasts, and radio/stations, allowing an authenticated user to request internal services or cloud metadata and potentially receive parsed or streamed response content. This issue is fixed in version 9.7.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
phanan/koel <= 9.7.0Patched in:
phanan/koel 9.7.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50552Medium· 6.3Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
CVE-2026-54494MediumKoel is a free, open-source music streaming solution
CVE-2026-54492Medium· 4.3Koel is a free, open-source music streaming solution
CVE-2026-54493High· 7.7Koel is a free, open-source music streaming solution
GHSA-8q6q-m837-fv64Medium· 6.4Koel has SSRF through Authenticated Subsonic podcast feed URLs
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents