HIGH
advplyr
CVE published 2026-08-05
CVE-2026-71209
The audiobookshelf application is vulnerable to an unauthenticated arbitrary file read due to improper handling of URL-encoded path parameters. This HIGH-severity vulnerability (CVSS 7.5) exists in the server/routers/Auth.js file and affects the CacheManager.handleCoverCache function. Users of audiobookshelf, especially those hosting the application publicly or with sensitive data, should be aware of this [truncated]