Hi,
On 2026-08-24 20:37:08, Pieter Lenaerts wrote:
The beets web ui is very limited in its functions, it is not fit for external
publication, number of users is probably very limited to begin with, attacks
would be very unpractical.
Therefore I think this is a very low risk vulnerability.
I propose we contact upstream for a fix and backport this into the
(old-)*stable distributions without treating this with special urgency.
Do you agree with my assessment and proposed actions?
@Alto angelo, would you like to contact upstream at their github repo
https://github.com/beetbox/beets ?
another option would be to patch out the bundled jquery.js and instead
use the file provided by the package libjs-jquery.
Best regards
Peter