CVE-2026-40089
Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its AP...
Affects 0 products across 5 vendors.
Attacker causes the server to make HTTP requests to attacker-chosen destinations, potentially reaching internal services.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Sonicverse Radio Audio Streaming Stack contains a Server-Side Request Forgery (SSRF) vulnerability in its API client, which could allow attackers to make requests to internal or external systems on behalf of the server.
BSID: BS-2026-GLOBAL-152170-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-40089?
What is the CVSS score for CVE-2026-40089?
Is CVE-2026-40089 actively exploited?
How do I remediate CVE-2026-40089?
What systems are affected by CVE-2026-40089?
| CVE ID | CVE-2026-40089 |
|---|---|
| BSID | BS-2026-GLOBAL-152170-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
| Published | 2026-04-09 |
| Last Modified | 2026-04-13 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner bash <(curl -fsSL https://sonicverse.short.gy/install-audiostack)) are affected. In these deployments, the dashboard accepts user-controlled URLs and passes them directly to a server-side HTTP client without sufficient validation. An authenticated operator can abuse this to make arbitrary HTTP requests from the dashboard backend to internal or external systems. This vulnerability is fixed with commit cb1ddbacafcb441549fe87d3eeabdb6a085325e4.
Source: NIST NVD / MITRE CVE Database
The vulnerability exists in the API client located at apps/dashboard/lib/api.ts. An attacker could exploit this SSRF vulnerability to send malicious requests to internal services, leading to unauthorized data access or other malicious activities.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Abuse | — | — |
| Client | — | — |
| Curl | — | — |
| Docker | — | — |
| Script | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 2ccb3fc4264f3461c69703349dd3f2688060ec2c460ec5e2dd57d6f1dd8cb5b06b2ac37e7081c92c4feeacf41eb6ae828a86515584c294108a972b64d9e9a0f0 |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →