Reflected Cross-Site Scripting Vulnerability in Audiobookshelf by Audiobookshelf Team
CVE-2025-46338
6.9MEDIUM
What is CVE-2025-46338?
Audiobookshelf, a self-hosted audiobook and podcast server, contains a vulnerability in the /api/upload endpoint affecting versions prior to 2.21.0. This security flaw arises from improper input handling, allowing attackers to execute reflected cross-site scripting (XSS) attacks. By submitting malevolent payloads in the libraryId field, an attacker could manipulate the server's error messages to reflect unverified inputs, leading to arbitrary JavaScript execution in a victim's browser. The issue has been addressed in version 2.21.0, underscoring the importance of input sanitization to prevent unauthorized script execution.
Affected Version(s)
audiobookshelf < 2.21.0
