Impact
Audiobookshelf, a self‑hosted audiobook and podcast server, contains a stored cross‑site scripting flaw in its Tooltip.vue component that can be triggered via malicious library metadata. Attackers with the ability to modify library entries can inject arbitrary JavaScript executed in any user’s browser, enabling session hijacking and data exfiltration, and the weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects the Audiobookshelf web application from the vendor advplyr in any release older than 2.32.0.
Risk and Exploitability
The flaw carries a CVSS score of 4.8, reflecting moderate risk, and an EPSS score of less than 1%, indicating a low likelihood of exploitation in the wild; it is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have library‑modification privileges, so the attack vector is typically internal or result of a compromised account.
OpenCVE Enrichment