CVE-2026-27974: Audiobooksheld VUlnerable to Stored XSS in WrappingMarquee.js via Audiobook Metadata (Mobile App Audio Player)
Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges (or control over a malicious podcast RSS feed) can execute code in victim users' WebViews, potentially leading to session hijacking, data exfiltration, and unauthorized access to native device APIs. audiobookshelf-app version 0.12.0-beta fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27974?
The severity of CVE-2026-27974 has not been explicitly rated but it is classified as a stored XSS vulnerability which can lead to significant security issues.
How do I fix CVE-2026-27974?
To fix CVE-2026-27974, upgrade your Audiobookshelf mobile application to version 0.12.0-beta or later.
What type of vulnerability is CVE-2026-27974?
CVE-2026-27974 is a stored cross-site scripting (XSS) vulnerability affecting the Audiobookshelf mobile application.
Which versions of Audiobookshelf are affected by CVE-2026-27974?
Versions of Audiobookshelf prior to 0.12.0-beta are affected by CVE-2026-27974.
What impact does CVE-2026-27974 have on users?
CVE-2026-27974 can allow attackers to inject malicious scripts into user sessions, potentially compromising user data and session integrity.