CVE-2023-51665

MEDIUM

audiobookshelf < 2.7.0 - Unauthenticated Server-Side Request Forgery in Auth.js

Title source: llm
STIX 2.1

Description

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.

Scores

CVSS v3 4.3
EPSS 0.0035
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
audiobookshelf/audiobookshelf < 2.7.0
Published Dec 27, 2023
Tracked Since Feb 18, 2026