CVE-2024-39307

Published
View on NVD ↗
CVSS v3
3.5
LOW
CVSS v2
N/A
Affected
1
PROJECT

Description

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute. This vulnerability was patched in version 0.8.1.

Kavita is a fast, feature rich, cross platform reading server. Built with the goal of being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family.
GitHubGitHub
10.8K