Audiobookshelf - Authentication Bypass
Audiobookshelf contains a path traversal caused by improper authentication-exemption check on URL-encoded paths in server/routers/Auth.js, letting unauthenticated attackers read arbitrary files, exploit requires crafted URL with encoded traversal sequences. References: https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-pg8v-5jcv-wrvw https://nvd.nist.gov/vuln/detail/CVE-2026-71209 Remediation: Update to the latest version with proper decoding and authentication checks for path parameters.
Used 2.3k times · domain, subdomain, ipv4