PT-2025-7059 · Unknown · Audiobookshelf

Swiftbird07

·

Published

2025-02-12

·

Updated

2025-02-12

·

CVE-2025-25205

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Audiobookshelf versions 2.17.0 through 2.19.0
Description: Audiobookshelf is a self-hosted audiobook and podcast server. A flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs containing substrings like "/api/items/1/cover" in a query parameter (?r=/api/items/1/cover) to partially bypass authentication or trigger server crashes under certain routes. This could lead to information disclosure of otherwise protected data and, in some cases, a complete denial of service (server crash) if downstream code expects an authenticated user object.
Recommendations: For versions 2.17.0 through 2.19.0, update to version 2.19.1 to resolve the issue. As a temporary workaround, consider restricting access to the /api/items/ endpoint and other vulnerable routes until a patch is applied. Avoid using the ?r= query parameter in the affected API endpoints until the issue is resolved.

Exploit

Fix

Resource Exhaustion

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-25205
GHSA-PG8V-5JCV-WRVW

Affected Products

Audiobookshelf