CVE-2026-42451

Source
https://cve.org/CVERecord?id=CVE-2026-42451
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42451.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42451
Aliases
  • GHSA-frv6-5wq5-9p24
Published
2026-05-08T22:51:21.920Z
Modified
2026-08-04T11:50:58.050594730Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L CVSS Calculator
Summary
Grimmory: Stored XSS via Malicious EPUB Enables Session Token Theft
Details

Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimmory's browser-based EPUB reader allows an attacker to embed arbitrary JavaScript in a crafted EPUB file. When a victim opens the book, the script executes in their browser with full access to the Grimmory application's session context. This can enable session token theft and account takeover, including administrative access if an administrator opens the affected book. This issue has been patched in version 2.3.1.

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-80"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42451.json"
}
References

Affected packages

Git / github.com/grimmory-tools/grimmory

Affected ranges

Type
GIT
Repo
https://github.com/grimmory-tools/grimmory
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.3.1"
        }
    ]
}

Affected versions

v2.*
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42451.json"