CVE-2026-27963

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration. Version 2.32.0 contains a patch for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:*

History

27 Feb 2026, 17:08

Type Values Removed Values Added
References () https://github.com/advplyr/audiobookshelf/commit/503f4611b221a5bde19024e657021670df204478 - () https://github.com/advplyr/audiobookshelf/commit/503f4611b221a5bde19024e657021670df204478 - Patch
References () https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-69cp-m725-wf78 - () https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-69cp-m725-wf78 - Exploit, Mitigation, Patch, Vendor Advisory
First Time Audiobookshelf
Audiobookshelf audiobookshelf
CPE cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:*

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Audiobookshelf es un servidor de audiolibros y podcasts autoalojado. Existe una vulnerabilidad de cross-site scripting (XSS) almacenado en las versiones anteriores a la 2.32.0 de la aplicación, la cual permite la ejecución arbitraria de JavaScript a través de metadatos de biblioteca maliciosos. Atacantes con privilegios de modificación de biblioteca pueden ejecutar código en los navegadores de los usuarios víctimas, lo que podría llevar al secuestro de sesión y a la exfiltración de datos. La versión 2.32.0 contiene un parche para el problema.

26 Feb 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 03:16

Updated : 2026-02-27 17:08


NVD link : CVE-2026-27963

Mitre link : CVE-2026-27963

CVE.ORG link : CVE-2026-27963


JSON object : View

Products Affected

audiobookshelf

  • audiobookshelf
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')