CVE-2025-57800
- EPSS 0.15%
- Veröffentlicht 22.08.2025 17:15:36
- Zuletzt bearbeitet 26.08.2025 21:37:01
Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshe...
CVE-2025-46338
- EPSS 0.06%
- Veröffentlicht 29.04.2025 04:34:44
- Zuletzt bearbeitet 09.05.2025 19:37:37
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting ma...
CVE-2025-25205
- EPSS 0.63%
- Veröffentlicht 12.02.2025 19:15:21
- Zuletzt bearbeitet 03.07.2025 00:58:22
Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Att...
CVE-2024-43797
- EPSS 0.29%
- Veröffentlicht 02.09.2024 18:15:36
- Zuletzt bearbeitet 13.09.2024 19:49:33
audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows ...
CVE-2024-35236
- EPSS 1.43%
- Veröffentlicht 27.05.2024 17:15:09
- Zuletzt bearbeitet 10.07.2025 17:32:33
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libr...
CVE-2023-51665
- EPSS 0.06%
- Veröffentlicht 27.12.2023 18:15:23
- Zuletzt bearbeitet 21.11.2024 08:38:33
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are...
CVE-2023-51697
- EPSS 0.06%
- Veröffentlicht 27.12.2023 18:15:23
- Zuletzt bearbeitet 21.11.2024 08:38:37
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `podcastUtils.js`. This vulnerability has been addressed in version 2.7.0....
CVE-2023-47619
- EPSS 0.12%
- Veröffentlicht 13.12.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 08:30:32
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This ...
CVE-2023-47624
- EPSS 0.12%
- Veröffentlicht 13.12.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 08:30:33
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may ...