Skip to content
Ubuntu 26.04 Beets Media Injection Vulnerability USN-8747-1 CVE-2026

Ubuntu 26.04 Beets Media Injection Vulnerability USN-8747-1 CVE-2026

Linuxsecurity LinuxSecurity Advisories September 10, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Beets could allow malicious media metadata to compromise its web interface. Software Description: - beets: music tagger and library organizer Details: It was discovered that Beets incorrectly escaped untrusted media metadata in its web interface. An attacker could possibly use this issue to inject arbitrary HTML or execute arbitrary JavaScript code in a user's browser.

Beets could allow malicious media metadata to compromise its web interface.

Software Description:

- beets: music tagger and library organizer

It was discovered that Beets incorrectly escaped untrusted media metadata

in its web interface. An attacker could possibly use this issue to inject

arbitrary HTML or execute arbitrary JavaScript code in a user's browser.

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS beets 2.5.1-4ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS beets 1.6.0-8ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS beets 1.6.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS beets 1.4.9-4ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS beets 1.4.6-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS beets 1.3.8+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8747-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases