Vulnerability Description
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration. Version 2.32.0 contains a patch for the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Audiobookshelf | Audiobookshelf | < 2.32.0 |
Related Weaknesses (CWE)
References
- https://github.com/advplyr/audiobookshelf/commit/503f4611b221a5bde19024e65702167Patch
- https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-69cp-m725-wf7ExploitMitigationPatch
FAQ
What is CVE-2026-27963?
CVE-2026-27963 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arb...
How severe is CVE-2026-27963?
CVE-2026-27963 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-27963?
Check the references section above for vendor advisories and patch information. Affected products include: Audiobookshelf Audiobookshelf.