CVE-2026-88868
nicheStored XSS in AVideo LiveLinks Plugin via Unsanitized Title and Description
AVideo, an open-source video streaming platform, contains a stored cross-site scripting (XSS) vulnerability in its LiveLinks plugin, where live-link title and description fields are saved without sanitization. A user holding the canStream permission can inject malicious JavaScript into those fields, and the script then executes in the browser of every visitor who opens the affected live-link page, including administrators, within the site origin. Because the payload fires against any viewer, an attacker could hijack sessions or perform actions as the victim (including admin users) within the site origin, consistent with the high confidentiality and integrity impacts in the CVSS 4.0 vector. All AVideo deployments running code through commit c3edcc274c389816d434acadac07ee78eaf330c1 with the LiveLinks plugin enabled are affected. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA's KEV.
What to do: Deploy an AVideo build newer than commit c3edcc274c389816d434acadac07ee78eaf330c1 once the patched release is available, and as an interim measure restrict the canStream permission to fully trusted users. Audit existing LiveLinks title and description values for injected HTML or JavaScript and remove any suspicious content. Administrators should avoid casually browsing live-link pages until patched, since their sessions are the most valuable target.
| AVideo (open-source project) AVideo with LiveLinks plugin | through commit c3edcc274c389816d434acadac07ee78eaf330c1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.