PatchSiren

advplyr CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM advplyr CVE published 2026-08-11

CVE-2026-73085

CVE-2026-73085 debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T17:19:16.557Z. Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting them to /au [truncated]

HIGH advplyr CVE published 2026-08-05

CVE-2026-71209

The audiobookshelf application is vulnerable to an unauthenticated arbitrary file read due to improper handling of URL-encoded path parameters. This HIGH-severity vulnerability (CVSS 7.5) exists in the server/routers/Auth.js file and affects the CacheManager.handleCoverCache function. Users of audiobookshelf, especially those hosting the application publicly or with sensitive data, should be aware of this [truncated]