PT-2025-7059 · Unknown · Audiobookshelf
Swiftbird07
·
Published
2025-02-12
·
Updated
2025-02-12
·
CVE-2025-25205
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Audiobookshelf versions 2.17.0 through 2.19.0
Description:
Audiobookshelf is a self-hosted audiobook and podcast server. A flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs containing substrings like "/api/items/1/cover" in a query parameter (?r=/api/items/1/cover) to partially bypass authentication or trigger server crashes under certain routes. This could lead to information disclosure of otherwise protected data and, in some cases, a complete denial of service (server crash) if downstream code expects an authenticated user object.
Recommendations:
For versions 2.17.0 through 2.19.0, update to version 2.19.1 to resolve the issue.
As a temporary workaround, consider restricting access to the
/api/items/ endpoint and other vulnerable routes until a patch is applied.
Avoid using the ?r= query parameter in the affected API endpoints until the issue is resolved.Exploit
Fix
Resource Exhaustion
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Audiobookshelf