CVE-2026-42888: Audiobookshelf: Path Traversal vulnerability in the audiobookshelf project
Published May 11, 2026
·Updated
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.js accepts a user-controlled file path without sufficient boundary validation to ensure it remains within the intended library directory. This vulnerability is fixed in 2.32.2.
Affected Software
1 affected component
Audiobookshelf Audiobookshelf<2.32.2
Event History
May 11, 2026
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionWeakness
Data Sourced
via NVD·09:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42888?
CVE-2026-42888 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2026-42888?
To fix CVE-2026-42888, update Audiobookshelf to version 2.32.2 or later.
3
What does CVE-2026-42888 affect?
CVE-2026-42888 affects Audiobookshelf versions prior to 2.32.2.
4
What type of vulnerability is CVE-2026-42888?
CVE-2026-42888 is a path traversal vulnerability.
5
What is the exploitability of CVE-2026-42888?
CVE-2026-42888 can be exploited to access files outside the intended directory.