CVE-2026-27963Disclosure(audiobookshelf / audiobookshelf)

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration. Version 2.32.0 contains a patch for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • audiobookshelf

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
audiobookshelf

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-26: 3Technical Details · 2026-02-26: 302-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27963 Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshe… https://www.cve.org/CVERecord?id=CVE-2026-27963

    Post summary

    The post announces a stored XSS vulnerability (CVE‑2026‑27963) affecting Audiobookshelf versions before 2.32.0.

    0000099
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27963 Stored XSS Vulnerability in Audiobookshelf Web Application Before 2.32.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27963

    Post summary

    CVE-2026-27963 is a stored XSS vulnerability affecting Audiobookshelf versions prior to 2.32.0, as disclosed in the provided text.

    0000039
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-27963 - Audiobookshelf has Stored XSS in Tooltip.vue via Audiobook Metadata Intel Report: https://ift.tt/Vsdb2nW

    Post summary

    A new CVE-2026-27963 vulnerability in Audiobookshelf is disclosed, describing a stored XSS flaw in Tooltip.vue triggered via audiobook metadata. No PoC, exploit, patch, or active exploitation details are provided.

    000006
    338 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaudiobookshelfaudiobookshelf---

Explore more