GHSA-xv8g-fj9h-6gmv
The `linkdave` server does not enforce authentication on its REST and WebSocket routes in versions prior to `0.1.5`. ### Impact An attacker with network access to the server port can: - Connect to the WebSocket endpoint (`/ws`) and receive a valid `session_id` in the `OpReady` response. - Use that session to invoke all REST player controls on any guild corresponding to their session id[1]. - Enumerate server statistics and runtime information via the unauthenticated `/stats` endpoint (still public after the fix). [1] If on [`>=0.1.0`](https://github.com/shi-gg/linkdave/releases/tag/v0.1.0), attackers are restricted to creating, controlling and deleting players created within their own session ID. ### Vulnerable Routes The following routes were entirely unauthenticated in `>= 0.0.1, < 0.1.5`: | Method | Path | Description | |--------|------|-------------| | `POST` | `/sessions/{session_id}/players/{guild_id}/play` | Start audio playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/pause` | Pause playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/resume` | Resume playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/stop` | Stop playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/seek` | Seek to position | | `PATCH` | `/sessions/{session_id}/players/{guild_id}/volume` | Set volume | | `DELETE` | `/sessions/{session_id}/players/{guild_id}` | Disconnect from voice channel | | `GET` | `/ws` | WebSocket event stream | ### Patches Update to [`0.1.5`](https://github.com/shi-gg/linkdave/commit/0f9a00d9d549b16278db81fce6dfec350c2abc01). ```diff - image: ghcr.io/shi-gg/linkdave:0.1.4 + image: ghcr.io/shi-gg/linkdave:latest ``` or ```sh docker pull ghcr.io/shi-gg/linkdave:latest ``` After upgrading, set the `LINKDAVE_PASSWORD` environment variable to a strong secret value. If this variable is left unset, the server will still accept all connections without authentication even on `>= 0.1.5`. **Server configuration (e.g.
Properties
- ghsa_id
- GHSA-xv8g-fj9h-6gmv
- severity
- critical
- summary
- Linkdave Missing Authentication on REST and WebSocket endpoints
- cve_id
- GHSA-xv8g-fj9h-6gmv
- is_ghsa_only
- true
- ghsa_published
- 2026-03-10T01:18:20Z
- source_url
- https://github.com/advisories/GHSA-xv8g-fj9h-6gmv
- ghsa_updated
- 2026-03-10T19:27:59Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph