CVE-2026-42888: Advplyr Audiobookshelf

Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.js accepts a user-controlled file path without sufficient boundary validation to ensure it remains within the intended library directory. This vulnerability is fixed in 2.32.2.

Affected products

  • Advplyr Audiobookshelf: before 2.33.2 (fixed in 2.33.2)

Published 2026-05-11. Last modified 2026-06-17.