CVE-2023-51697: Audiobookshelf
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `podcastUtils.js`. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.
Affected products
- Audiobookshelf Audiobookshelf: before 2.7.0 (fixed in 2.7.0)
Published 2023-12-27. Last modified 2026-06-17.