Reflected Cross-Site Scripting Vulnerability in Audiobookshelf by Audiobookshelf Team
CVE-2025-46338

6.9MEDIUM

Key Information:

Vendor

Advplyr

Vendor
CVE Published:
29 April 2025

What is CVE-2025-46338?

Audiobookshelf, a self-hosted audiobook and podcast server, contains a vulnerability in the /api/upload endpoint affecting versions prior to 2.21.0. This security flaw arises from improper input handling, allowing attackers to execute reflected cross-site scripting (XSS) attacks. By submitting malevolent payloads in the libraryId field, an attacker could manipulate the server's error messages to reflect unverified inputs, leading to arbitrary JavaScript execution in a victim's browser. The issue has been addressed in version 2.21.0, underscoring the importance of input sanitization to prevent unauthorized script execution.

Affected Version(s)

audiobookshelf < 2.21.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-46338 : Reflected Cross-Site Scripting Vulnerability in Audiobookshelf by Audiobookshelf Team