ZeroHour

CVE-2026-88868

niche

Stored XSS in AVideo LiveLinks Plugin via Unsanitized Title and Description

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

AVideo, an open-source video streaming platform, contains a stored cross-site scripting (XSS) vulnerability in its LiveLinks plugin, where live-link title and description fields are saved without sanitization. A user holding the canStream permission can inject malicious JavaScript into those fields, and the script then executes in the browser of every visitor who opens the affected live-link page, including administrators, within the site origin. Because the payload fires against any viewer, an attacker could hijack sessions or perform actions as the victim (including admin users) within the site origin, consistent with the high confidentiality and integrity impacts in the CVSS 4.0 vector. All AVideo deployments running code through commit c3edcc274c389816d434acadac07ee78eaf330c1 with the LiveLinks plugin enabled are affected. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA's KEV.

What to do: Deploy an AVideo build newer than commit c3edcc274c389816d434acadac07ee78eaf330c1 once the patched release is available, and as an interim measure restrict the canStream permission to fully trusted users. Audit existing LiveLinks title and description values for injected HTML or JavaScript and remove any suspicious content. Administrators should avoid casually browsing live-link pages until patched, since their sessions are the most valuable target.

Affected
AVideo (open-source project) AVideo with LiveLinks pluginthrough commit c3edcc274c389816d434acadac07ee78eaf330c1
Estimated exposure
nichelikely on the order of a few thousand self-hosted instances at most (estimate; no authoritative install counts) — AVideo is a niche self-hosted open-source video streaming platform and only deployments with the LiveLinks plugin enabled are vulnerable, so exposure is expected to be limited to a small self-hosted footprint rather than mass-market scale.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.