Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104058— Podgrab Missing Authentication on WebSocket /ws Endpoint

Quick assessment

Affected
akhilrex podgrab
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Podgrab 存在一个缺失身份验证的漏洞: WebSocket 路由被注册在根 Gin 引擎上,而非受 BasicAuth(基本身份验证)保护的子路由组中。因此,即使已配置 环境变量,未经身份验证的网络客户端仍可建立连接。 攻击者可加入 集合,捕获包含由客户端提供的玩家标识符的 广播消息,并在 消息中重放这些标识符,从而劫持原本专供已认证用户使用的队列载荷。这将导致剧集 ID、标题以及服务器端文件路径等敏感信息泄露,并可能干扰合法用户的正常播放。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104058

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Podgrab Missing Authentication on WebSocket /ws Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
akhilrex podgrab 0 ~ 032248091294dbf5b6a439a5afd93788a7cc647f -

II. Public POCs for CVE-2026-104058

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104058

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-104058 (1)

Other References for CVE-2026-104058 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104058

No comments yet


Leave a comment