CVE-2026-42052Disclosure

LOWCVSS 6.0 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML escaping is only performed by <%- ... %>. Rendered output is then inserted with .html(...), allowing attacker-controlled markup to become active DOM. This issue has been patched in version 2.10.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-04: 2Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-04: 205-04
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42052 Cross-Site Scripting in Beets Media Library Management System Below 2.10.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42052

    Post summary

    The post announces CVE-2026-42052 as an XSS flaw in Beets Media below v2.10.0, offering no PoC, exploit, or patch details.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-42052 Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode &lt;%= ... %&gt; for untrusted metadat… https://www.cve.org/CVERecord?id=CVE-2026-42052

    Post summary

    The post highlights CVE‑2026‑42052 in Beets’ web UI, noting insecure underscore templating prior to v2.10.0 and implying that upgrading to the latest version mitigates the issue.

    0000099
    57.4K followersView on X

Explore more