Junglewise Threat Intelligence

CVE-2026-42885: Audiobookshelf path traversal in filesystem existence check

CVE-2026-42885 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Advplyr Audiobookshelf. Vendors: Advplyr.

Executive brief

Audiobookshelf is a self-hosted server for managing audiobooks and podcasts. A security flaw allows users with upload permissions to bypass folder restrictions and check for the existence of files or directories they are not authorized to see. While attackers cannot read the contents of these files, they can map out the server's file system and identify private data stored in folders with similar names.

Technical details

A path traversal vulnerability exists in the `checkPathExists` handler within `server/controllers/FileSystemController.js`. The application uses `String.startsWith()` to verify that a resolved path remains within the intended library directory. However, this string-based check fails to account for path boundaries, allowing an attacker to access sibling directories that share a common prefix (e.g., `/audiobooks` vs `/audiobooks-private`). An authenticated attacker with `canUpload` permissions can use `../` sequences to resolve paths outside their library; if the resulting string still starts with the library's base path, the check passes. This allows for boolean file existence probing via the `POST /api/filesystem/pathexists` endpoint. The issue is resolved in version 2.32.2 by using a proper path-aware comparison utility.

Affected products

  • advplyr Audiobookshelf < 2.32.2

Timeline

  • 2026-04-28: advisory: GitHub Security Advisory published
  • 2026-05-11: disclosed: CVE published to NVD
  • 2026-05-11: patched: Fix released in version 2.32.2

References

Related threats