Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration. Version 2.32.0 contains a patch for the issue.
References
| Link | Resource |
|---|---|
| https://github.com/advplyr/audiobookshelf/commit/503f4611b221a5bde19024e657021670df204478 | Patch |
| https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-69cp-m725-wf78 | Exploit Mitigation Patch Vendor Advisory |
Configurations
History
27 Feb 2026, 17:08
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/advplyr/audiobookshelf/commit/503f4611b221a5bde19024e657021670df204478 - Patch | |
| References | () https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-69cp-m725-wf78 - Exploit, Mitigation, Patch, Vendor Advisory | |
| First Time |
Audiobookshelf
Audiobookshelf audiobookshelf |
|
| CPE | cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:* |
27 Feb 2026, 14:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Feb 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-26 03:16
Updated : 2026-02-27 17:08
NVD link : CVE-2026-27963
Mitre link : CVE-2026-27963
CVE.ORG link : CVE-2026-27963
JSON object : View
Products Affected
audiobookshelf
- audiobookshelf
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
