PT-2026-22118 · Unknown · Audiobookshelf

Michael-Tyl

·

Published

2026-02-26

·

Updated

2026-02-26

·

CVE-2026-27963

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Audiobookshelf versions prior to 2.32.0
Description Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) issue exists that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration.
Recommendations Update to version 2.32.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27963
GHSA-69CP-M725-WF78

Affected Products

Audiobookshelf