Cross-Site Scripting Vulnerability in Audiobookshelf Mobile Application
CVE-2026-27974
4.8MEDIUM
What is CVE-2026-27974?
A cross-site scripting vulnerability in the Audiobookshelf mobile application allows attackers to inject arbitrary JavaScript through compromised library metadata. This flaw exists in versions prior to 0.12.0-beta, enabling those with library modification privileges or control of a malicious podcast RSS feed to execute harmful code in the WebViews of users. Such attacks can lead to serious security implications, including session hijacking, unauthorized data access, and exploitation of device APIs. Users are advised to upgrade to version 0.12.0-beta to mitigate this risk.
Affected Version(s)
audiobookshelf-app < 0.12.0-beta
