PT-2026-22118 · Unknown · Audiobookshelf

Michael-Tyl

·

Publicado

2026-02-26

·

Atualizado

2026-02-26

·

CVE-2026-27963

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Audiobookshelf versions prior to 2.32.0
Description Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) issue exists that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration.
Recommendations Update to version 2.32.0 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27963
GHSA-69CP-M725-WF78

Produtos afetados

Audiobookshelf