Upstream issue filed at: https://github.com/beetbox/beets/issues/6949
Gajendra On Tue, Aug 25, 2026 at 1:22 AM Moritz Mühlenhoff <[email protected]> wrote: > On Mon, Aug 24, 2026 at 08:57:02PM +0200, Peter Wienemann wrote: > > Hi, > > > > On 2026-08-24 20:37:08, Pieter Lenaerts wrote: > > > The beets web ui is very limited in its functions, it is not fit for > external > > > publication, number of users is probably very limited to begin with, > attacks > > > would be very unpractical. > > > > > > Therefore I think this is a very low risk vulnerability. > > > > > > I propose we contact upstream for a fix and backport this into the > > > (old-)*stable distributions without treating this with special urgency. > > > > > > Do you agree with my assessment and proposed actions? > > Agreed, there's no need for a DSA. It can either be fixed via a point > release or we can also simply ignore it for stable entirely. > > > > @Alto angelo, would you like to contact upstream at their github repo > > > https://github.com/beetbox/beets ? > > > > another option would be to patch out the bundled jquery.js and instead > use > > the file provided by the package libjs-jquery. > > That would be the best fix for forky indeed. > > Cheers, > Moritz >

