beets
music library manager and MusicBrainz tagger
Activity
- Latest release
- 1w ago
- Total releases
- 75
- Cadence
- ~35 days
- Last 12 months
- 15
Reach
- Stars
- 15.7k
Details
- License
- MIT
- First release
- Jun 17, 2010
| Version | Released | |
|---|---|---|
2.14.0
minor
| ||
2.13.1
patch
| ||
2.13.0
minor
| ||
2.12.0
minor
| ||
2.11.0
minor
| ||
2.10.0
minor
| ||
2.9.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.8.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.7.1
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.7.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.6.2
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.6.1
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.6.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.5.1
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.3.1
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.9
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.8
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.7
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.6
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.5
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.4
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.3
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.1
minor
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.19
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.18
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.17
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.16
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.15
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.14
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.13
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.12
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.11
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.10
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.9
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.8
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.7
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.6
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.5
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.4
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.3
patch
1 CVE
CVE-2026-42052
PYSEC-2026-2397
GHSA-3gxm-wfjx-m847
Jul 13, 2026
beets has a Cross-site Scripting vulnerability
High
Network
Low
None
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered. Overview
Root CauseThe bundled web UI uses Underscore template interpolation mode Source-to-Sink Chain
Exploitation Preconditions
RiskStored payload executes in the web UI context and can perform actions available to that origin. ImpactAttacker can run arbitrary JavaScript in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. Remediation
Affected versions
1.0.0
1.0b1
1.0b10
1.0b11
1.0b12
1.0b13
1.0b14
1.0b15
1.0b2
1.0b3
1.0b4
1.0b5
+ 58 more Show less
1.0b6
1.0b7
1.0b8
1.0b9
1.0rc1
1.0rc2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.6.0
1.6.1
2.0.0
2.1.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.10.0
References
Updated Jul 13, 2026 · Source: OSV.dev |