Upstream issue filed at:
https://github.com/beetbox/beets/issues/6949

Gajendra

On Tue, Aug 25, 2026 at 1:22 AM Moritz Mühlenhoff <[email protected]> wrote:

> On Mon, Aug 24, 2026 at 08:57:02PM +0200, Peter Wienemann wrote:
> > Hi,
> >
> > On 2026-08-24 20:37:08, Pieter Lenaerts wrote:
> > > The beets web ui is very limited in its functions, it is not fit for
> external
> > > publication, number of users is probably very limited to begin with,
> attacks
> > > would be very unpractical.
> > >
> > > Therefore I think this is a very low risk vulnerability.
> > >
> > > I propose we contact upstream for a fix and backport this into the
> > > (old-)*stable distributions without treating this with special urgency.
> > >
> > > Do you agree with my assessment and proposed actions?
>
> Agreed, there's no need for a DSA. It can either be fixed via a point
> release or we can also simply ignore it for stable entirely.
>
> > > @Alto angelo, would you like to contact upstream at their github repo
> > > https://github.com/beetbox/beets ?
> >
> > another option would be to patch out the bundled jquery.js and instead
> use
> > the file provided by the package libjs-jquery.
>
> That would be the best fix for forky indeed.
>
> Cheers,
>         Moritz
>

Reply via email to