CVE-2025-25205 describes an authentication bypass vulnerability in Audiobookshelf versions 2.17.0 through 2.19.0. An unauthenticated attacker can craft URLs with specific substrings in query parameters to partially bypass authentication, potentially leading to information disclosure of protected data. In some cases, this flaw can also trigger a denial of service by crashing the server. The vulnerability has a CVSS score of 8.2 (HIGH), indicating a critical severity. It is exploitable over the network with low attack complexity and no user interaction required. The primary impacts are partial confidentiality loss and complete availability loss. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.17.0, < 2.19.1CPE matchmatch criteria | cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.