Package: beets
Version: 2.13.1-1
Severity: important
Tags: security
X-Debbugs-Cc: [email protected], [email protected]

The beets web plugin ships a bundled copy of jQuery at:
  beetsplug/web/static/jquery.js

This version is below 3.5.0 and is vulnerable to XSS via DOM
manipulation methods (CVE-2020-11022, CVE-2020-11023). Since beets
actively serves this file to users via its web plugin interface,
the XSS vulnerability is directly exploitable.

Please update the bundled jQuery to 3.5.0 or later, or use the
system libjs-jquery package instead.

Reference:
  https://security-tracker.debian.org/tracker/CVE-2020-11022

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra Nath Soren
[email protected]

Reply via email to