CVE-2026-40089

CRITICAL

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its AP...

Affects 0 products across 5 vendors.

BCS6.25
CVSS 3.19.9
EPSS0.2%
Percentile14th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact.
CWE Weakness Definitions
CWE-918: Server-Side Request Forgery (SSRF)

Attacker causes the server to make HTTP requests to attacker-chosen destinations, potentially reaching internal services.

Related Attack Patterns (CAPEC)
CAPEC-664 Server Side Request Forgery
via CWE-918

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Sonicverse Radio Audio Streaming Stack contains a Server-Side Request Forgery (SSRF) vulnerability in its API client, which could allow attackers to make requests to internal or external systems on behalf of the server.

BSID: BS-2026-GLOBAL-152170-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-40089?
Sonicverse Radio Audio Streaming Stack contains a Server-Side Request Forgery (SSRF) vulnerability in its API client, which could allow attackers to make requests to internal or external systems on behalf of the server.
What is the CVSS score for CVE-2026-40089?
CVE-2026-40089 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L. EPSS: 0.2%.
Is CVE-2026-40089 actively exploited?
No confirmed active exploitation of CVE-2026-40089 as of 2026-05-30.
How do I remediate CVE-2026-40089?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-40089?
CVE-2026-40089 affects: Abuse, Client, Curl, Docker, Script.
Vulnerability Details
CVE IDCVE-2026-40089
BSIDBS-2026-GLOBAL-152170-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Published2026-04-09
Last Modified2026-04-13
ICS Relevance15%
Weakness (CWE)
Domains
CLOUD
SourceNVD
Official Description

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner bash <(curl -fsSL https://sonicverse.short.gy/install-audiostack)) are affected. In these deployments, the dashboard accepts user-controlled URLs and passes them directly to a server-side HTTP client without sufficient validation. An authenticated operator can abuse this to make arbitrary HTTP requests from the dashboard backend to internal or external systems. This vulnerability is fixed with commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the API client located at apps/dashboard/lib/api.ts. An attacker could exploit this SSRF vulnerability to send malicious requests to internal services, leading to unauthorized data access or other malicious activities.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Abuse &mdash;
Client &mdash;
Curl &mdash;
Docker &mdash;
Script &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 120 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash2ccb3fc4264f3461c69703349dd3f2688060ec2c460ec5e2dd57d6f1dd8cb5b06b2ac37e7081c92c4feeacf41eb6ae828a86515584c294108a972b64d9e9a0f0
Related CVEs affecting Abuse
CVE-1999-0512 10.0 A mail server is explicitly configured to allow SMTP mail relay, which allows... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2025-4378 10.0 Cleartext Transmission of Sensitive Information, Use of Hard-coded Credential... CVE-2024-28189 10.0 Judge0 is an open-source online code execution system. The application uses t... CVE-2026-25035 9.8 Authentication Bypass Using an Alternate Path or Channel vulnerability in Was...
View all Abuse CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →