CVE-2026-89255
nicheStored Cross-Site Scripting in AVideo LoginControl Plugin
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting flaw (CWE-79) in its LoginControl plugin, which echoes user-supplied PGP public keys into a textarea element without HTML-encoding. An authenticated attacker can submit a crafted public key containing malicious JavaScript, which then executes in an administrator's browser session when the administrator opens that user's profile tab. Because the injected script runs with administrator privileges, the attacker can perform administrative actions such as changing settings or accounts, potentially leading to full administrative compromise of the AVideo instance. Any AVideo deployment with the LoginControl plugin enabled is affected, while sites not using the plugin are not exposed. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and no in-the-wild exploitation has been reported; it is rated critical (CVSS 4.0: 9.3).
What to do: Upgrade AVideo to a build that includes the fix (i.e., newer than commit c3edcc274c389816d434acadac07ee78eaf330c1) as soon as a patched release is available. Until patching, disable the LoginControl plugin or restrict PGP public key submission to trusted users, and audit stored user PGP keys for embedded HTML or script content. Administrators should also avoid opening untrusted users' profile tabs until the fix is applied.
| AVideo (open-source video platform project) AVideo - LoginControl plugin | through commit c3edcc274c389816d434acadac07ee78eaf330c1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab.
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.