Vulnerability Description
Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs containing substrings like "/api/items/1/cover" in a query parameter (?r=/api/items/1/cover) to partially bypass authentication or trigger server crashes under certain routes. This could lead to information disclosure of otherwise protected data and, in some cases, a complete denial of service (server crash) if downstream code expects an authenticated user object. Version 2.19.1 contains a patch for the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Audiobookshelf | Audiobookshelf | >= 2.17.0, < 2.19.1 |
Related Weaknesses (CWE)
References
- https://github.com/advplyr/audiobookshelf/blob/1a3d70d04100924d41391acb55bd8ddcaProduct
- https://github.com/advplyr/audiobookshelf/commit/bf8407274e3ee300af1927ee660d078Patch
- https://github.com/advplyr/audiobookshelf/commit/ec6537656925a43871b07cfee12c9f3Patch
- https://github.com/advplyr/audiobookshelf/pull/3584Issue TrackingPatch
- https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-pg8v-5jcv-wrvExploitVendor Advisory
FAQ
What is CVE-2025-25205?
CVE-2025-25205 is a vulnerability with a CVSS score of 8.2 (HIGH). Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match...
How severe is CVE-2025-25205?
CVE-2025-25205 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25205?
Check the references section above for vendor advisories and patch information. Affected products include: Audiobookshelf Audiobookshelf.