Cross-Site Scripting Vulnerability in Audiobookshelf Mobile Application
CVE-2026-27974

4.8MEDIUM

Key Information:

Vendor

Advplyr

Vendor
CVE Published:
26 February 2026

What is CVE-2026-27974?

A cross-site scripting vulnerability in the Audiobookshelf mobile application allows attackers to inject arbitrary JavaScript through compromised library metadata. This flaw exists in versions prior to 0.12.0-beta, enabling those with library modification privileges or control of a malicious podcast RSS feed to execute harmful code in the WebViews of users. Such attacks can lead to serious security implications, including session hijacking, unauthorized data access, and exploitation of device APIs. Users are advised to upgrade to version 0.12.0-beta to mitigate this risk.

Affected Version(s)

audiobookshelf-app < 0.12.0-beta

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.