gonic has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was June 2026 with 3. The median CVSS is 7.1 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-49340High· 8.1gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host45CVE-2026-49339High· 7.1gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists39CVE-2026-49338High· 7.1Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)39
gonic vulnerabilities
CVEs affecting gonic, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-49340High· 8.1gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.43%via GHSA
CVE-2026-49339High· 7.1gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.39%via GHSA
CVE-2026-49338High· 7.1Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.29%via GHSA