Audiobookshelf

Audiobookshelf

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 22.08.2025 17:15:36
  • Zuletzt bearbeitet 26.08.2025 21:37:01

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshe...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 29.04.2025 04:34:44
  • Zuletzt bearbeitet 09.05.2025 19:37:37

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting ma...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 12.02.2025 19:15:21
  • Zuletzt bearbeitet 03.07.2025 00:58:22

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Att...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 02.09.2024 18:15:36
  • Zuletzt bearbeitet 13.09.2024 19:49:33

audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows ...

Exploit
  • EPSS 1.43%
  • Veröffentlicht 27.05.2024 17:15:09
  • Zuletzt bearbeitet 10.07.2025 17:32:33

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libr...

  • EPSS 0.06%
  • Veröffentlicht 27.12.2023 18:15:23
  • Zuletzt bearbeitet 21.11.2024 08:38:33

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are...

  • EPSS 0.06%
  • Veröffentlicht 27.12.2023 18:15:23
  • Zuletzt bearbeitet 21.11.2024 08:38:37

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `podcastUtils.js`. This vulnerability has been addressed in version 2.7.0....

Exploit
  • EPSS 0.12%
  • Veröffentlicht 13.12.2023 21:15:07
  • Zuletzt bearbeitet 21.11.2024 08:30:32

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This ...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 13.12.2023 21:15:07
  • Zuletzt bearbeitet 21.11.2024 08:30:33

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may ...