CVE-2026-42888

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.js accepts a user-controlled file path without sufficient boundary validation to ensure it remains within the intended library directory. This vulnerability is fixed in 2.32.2.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-05-11 21:19

Updated : 2026-06-17 10:48


NVD link : CVE-2026-42888

Mitre link : CVE-2026-42888

CVE.ORG link : CVE-2026-42888


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')