PT-2026-39837 · Unknown · Audiobookshelf

·

CVE-2026-42888

·

Published

2026-05-11

·

Updated

2026-05-11

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Audiobookshelf versions prior to 2.32.2
Description The podcast creation endpoint at 'server/controllers/PodcastController.js' accepts a user-controlled file path without sufficient boundary validation. This lack of validation allows the path to extend beyond the intended library directory, potentially leading to unauthorized file system access.
Recommendations Update to version 2.32.2.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42888
GHSA-PHCH-9734-WRP3

Affected Products

Audiobookshelf