criticalVulnerability

GHSA-xv8g-fj9h-6gmv

The `linkdave` server does not enforce authentication on its REST and WebSocket routes in versions prior to `0.1.5`. ### Impact An attacker with network access to the server port can: - Connect to the WebSocket endpoint (`/ws`) and receive a valid `session_id` in the `OpReady` response. - Use that session to invoke all REST player controls on any guild corresponding to their session id[1]. - Enumerate server statistics and runtime information via the unauthenticated `/stats` endpoint (still public after the fix). [1] If on [`>=0.1.0`](https://github.com/shi-gg/linkdave/releases/tag/v0.1.0), attackers are restricted to creating, controlling and deleting players created within their own session ID. ### Vulnerable Routes The following routes were entirely unauthenticated in `>= 0.0.1, < 0.1.5`: | Method | Path | Description | |--------|------|-------------| | `POST` | `/sessions/{session_id}/players/{guild_id}/play` | Start audio playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/pause` | Pause playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/resume` | Resume playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/stop` | Stop playback | | `POST` | `/sessions/{session_id}/players/{guild_id}/seek` | Seek to position | | `PATCH` | `/sessions/{session_id}/players/{guild_id}/volume` | Set volume | | `DELETE` | `/sessions/{session_id}/players/{guild_id}` | Disconnect from voice channel | | `GET` | `/ws` | WebSocket event stream | ### Patches Update to [`0.1.5`](https://github.com/shi-gg/linkdave/commit/0f9a00d9d549b16278db81fce6dfec350c2abc01). ```diff - image: ghcr.io/shi-gg/linkdave:0.1.4 + image: ghcr.io/shi-gg/linkdave:latest ``` or ```sh docker pull ghcr.io/shi-gg/linkdave:latest ``` After upgrading, set the `LINKDAVE_PASSWORD` environment variable to a strong secret value. If this variable is left unset, the server will still accept all connections without authentication even on `>= 0.1.5`. **Server configuration (e.g.

Properties

ghsa_id
GHSA-xv8g-fj9h-6gmv
severity
critical
summary
Linkdave Missing Authentication on REST and WebSocket endpoints
cve_id
GHSA-xv8g-fj9h-6gmv
is_ghsa_only
true
ghsa_published
2026-03-10T01:18:20Z
source_url
https://github.com/advisories/GHSA-xv8g-fj9h-6gmv
ghsa_updated
2026-03-10T19:27:59Z

Related Entities (3)

AFFECTS (1)

[Software]go/github.com/shi-gg/linkdave

HAS_WEAKNESS (1)

[Weakness]Missing Authentication for Critical Function

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-xv8g-fj9h-6gmv — Ninja Signal Threat Intelligence | Ninja Signal