Activity log
- Created suggestion
beets is Vulnerable to XSS
Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template interpolation mode <%= ... %> for untrusted metadata fields. In this runtime, <%= ... %> is raw insertion and HTML escaping is only performed by <%- ... %>. Rendered output is then inserted with .html(...), allowing attacker-controlled markup to become active DOM. This issue has been patched in version 2.10.0.
References
-
https://github.com/beetbox/beets/security/advisories/GHSA-3gxm-wfjx-m847 x_refsource_CONFIRM
-
https://github.com/beetbox/beets/releases/tag/v2.10.0 x_refsource_MISC
Affected products
- ==< 2.10.0
Matching in nixpkgs
pkgs.beets
Music tagger and library organizer
pkgs.beets-minimal
Music tagger and library organizer
pkgs.pkgsRocm.beets
Music tagger and library organizer
pkgs.python312Packages.beets
Music tagger and library organizer
pkgs.python313Packages.beets
Music tagger and library organizer
pkgs.python314Packages.beets
Music tagger and library organizer
pkgs.pkgsRocm.python3Packages.beets
Music tagger and library organizer
pkgs.python312Packages.beets-audible
Beets-audible: Organize Your Audiobook Collection With Beets
pkgs.python312Packages.beets-minimal
Music tagger and library organizer
pkgs.python313Packages.beets-audible
Beets-audible: Organize Your Audiobook Collection With Beets
pkgs.python313Packages.beets-minimal
Music tagger and library organizer
pkgs.python314Packages.beets-audible
Beets-audible: Organize Your Audiobook Collection With Beets
pkgs.python314Packages.beets-minimal
Music tagger and library organizer
pkgs.python312Packages.beets-alternatives
Beets plugin to manage external files
pkgs.python313Packages.beets-alternatives
Beets plugin to manage external files
pkgs.python314Packages.beets-alternatives
Beets plugin to manage external files
pkgs.pkgsRocm.python3Packages.beets-audible
Beets-audible: Organize Your Audiobook Collection With Beets
Package maintainers
-
@pjones Peter Jones <pjones@devalot.com>
-
@lovesegfault Bernardo Meurer <meurerbernardo@gmail.com>
-
@doronbehar Doron Behar <me@doronbehar.com>
-
@astratagem Chris Montgomery <chmont@protonmail.com>
-
@aszlig aszlig <aszlig@nix.build>
-
@jwillikers Jordan Williams <jordan@jwillikers.com>