CVE-2026-42451Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimmory's browser-based EPUB reader allows an attacker to embed arbitrary JavaScript in a crafted EPUB file. When a victim opens the book, the script executes in their browser with full access to the Grimmory application's session context. This can enable session token theft and account takeover, including administrative access if an administrator opens the affected book. This issue has been patched in version 2.3.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-09: 2Technical Details · 2026-05-09: 205-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42451 Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimmory's browser-based EPUB reader allows an… https://www.cve.org/CVERecord?id=CVE-2026-42451

    Post summary

    The text announces a stored XSS flaw (CVE-2026-42451) affecting Grimmory prior to version 2.3.1, with no evidence of exploitation or patch information.

    0001092
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42451 Stored Cross-Site Scripting in Grimmory EPUB Reader Prior to Version 2.3.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42451

    Post summary

    The text announces a stored XSS vulnerability in Grimmory EPUB Reader before version 2.3.1, detailing the affected product and vulnerability type.

    0000036
    4.0K followersView on X

Explore more