Sonarr Path Traversal Vulnerability Allowing Unauthenticated File Read on Windows

Vulnerability

A path traversal vulnerability has been identified in Sonarr, a PVR application for Usenet and BitTorrent users. This issue affects versions in the 4.x branch prior to 4.0.17.2950 and is exclusive to Windows systems. The vulnerability allows an unauthenticated remote attacker to read any file accessible by the Sonarr process. This includes application configuration files containing API keys and database credentials, Windows system files, and any user-accessible files on the same drive. The vulnerability arises because files returned from the web server were not restricted to the intended directory, potentially exposing sensitive information through the API.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files, including application configuration files with API keys and database credentials, Windows system files, and other user-accessible files on the same drive.

Remediation

Users can upgrade to Sonarr version 4.0.17.2950 in the nightly/develop branch or version 4.0.17.2952 for stable/main releases. For those unable to upgrade, the application can be hosted on a secure internal network and accessed via VPN, Tailscale, or a similar solution.

Added: Mar 25, 2026, 9:57 PM
Updated: Mar 25, 2026, 9:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.7
exploitability
7.0
remediation
0.0
relevance
4.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.