Package: beets Version: 2.13.1-1 Severity: important Tags: security X-Debbugs-Cc: [email protected], [email protected]
The beets web plugin ships a bundled copy of jQuery at: beetsplug/web/static/jquery.js This version is below 3.5.0 and is vulnerable to XSS via DOM manipulation methods (CVE-2020-11022, CVE-2020-11023). Since beets actively serves this file to users via its web plugin interface, the XSS vulnerability is directly exploitable. Please update the bundled jQuery to 3.5.0 or later, or use the system libjs-jquery package instead. Reference: https://security-tracker.debian.org/tracker/CVE-2020-11022 Found by: Attack of the Clones GSoC 2026 pipeline (salsa.debian.org/rouca/gsoc2026) Gajendra Nath Soren [email protected]

