CVE-2026-71209: audiobookshelf: %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route parameter before handler code runs, so a %2F-encoded '../' sequence in :id (e.g. ..%2f..%2f..%2ftmp%2fpwned) passes the literal-path auth-exemption check while resolving to a real path-traversal payload once decoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check. This bypasses the fix applied for CVE-2025-25205 (which anchored the exemption regex and switched it to req.path) and results in unauthenticated arbitrary file read of any file matching the pattern <width>[x<height>].<ext> that the service account can read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71209?
The severity of CVE-2026-71209 is high, rated at 7.5.
What is the risk associated with CVE-2026-71209?
CVE-2026-71209 has a risk score of 43.
How does CVE-2026-71209 impact Audiobookshelf?
CVE-2026-71209 allows unauthenticated path traversal due to an encoding discrepancy in the regex check for cover/image routes.
How do I fix CVE-2026-71209 in Audiobookshelf?
To fix CVE-2026-71209, update Audiobookshelf to the latest version where the vulnerability is patched.
What type of vulnerability is CVE-2026-71209?
CVE-2026-71209 is classified as a Path Traversal vulnerability.