CVE-2026-42887: Advplyr Audiobookshelf

Medium severity, CVSS 4.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulnerability exists in the Login Page due to improper sanitization of the authLoginCustomMessage field of the /api/auth-settings endpoint. An attacker with administrative privileges can inject arbitrary HTML/JavaScript that will be rendered on the login page for all users. This vulnerability is fixed in 2.33.0.

Affected products

  • Advplyr Audiobookshelf: before 2.33.0 (fixed in 2.33.0)

Published 2026-05-11. Last modified 2026-06-17.