Stored Cross-Site Scripting Vulnerability in Audiobookshelf by Audiobookshelf
CVE-2026-27963
4.8MEDIUM
What is CVE-2026-27963?
The Audiobookshelf web application has a stored cross-site scripting security flaw that allows attackers with library modification privileges to inject arbitrary JavaScript through manipulated library metadata. If exploited, this vulnerability could lead to unauthorized code execution in the browsers of users accessing the affected application. Such attacks may facilitate session hijacking and sensitive data exposure. Users are advised to upgrade to version 2.32.0 or later, which addresses this vulnerability.
Affected Version(s)
audiobookshelf < 2.32.0
