An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.
https://oxnan.com/posts/Snapcast_jsonrpc_rce
https://lists.debian.org/debian-lts-announce/2025/07/msg00015.html