Report: CVE-2026-42887 - Audiobookshelf: Stored Cross-Site Scripting in Login Page Custom Message

Report: CVE-2026-42887 - Audiobookshelf: Stored Cross-Site Scripting in Login Page Custom Message

CVE ID :CVE-2026-42887 Published : May 11, 2026, 8:25 p.m. | 36 minutes ago Description :Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulnerability exists in the Login Page due to improper sanitization of the authLoginCustomMessage field of the /api/auth-settings endpoint. An attacker with administrative privileges can inject arbitrary HTML/JavaScript that will be rendered on the login page for all users. This vulnerability is fixed in 2.33.0. Severity: 4.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 11, 2026
Impact: XSS