CVE-2026-27568

EPSS 0.01%

AVideo has Stored Cross-Site Scripting via Markdown Comment Injection

Published: 2/20/2026Modified: 2/24/2026
Also known as:GHSA-rcqw-6466-3mv7

Description

## Vulnerability Type Stored Cross-Site Scripting (XSS) — CWE-79. ## Affected Product/Versions AVideo 18.0. ## Root Cause Summary AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficiently sanitized, allowing `javascript:` URIs to be rendered as clickable links. ## Impact Summary An authenticated low-privilege attacker can post a malicious comment that injects persistent JavaScript. When another user clicks the link, the attacker can perform actions such as session hijacking, privilege escalation (including admin takeover), and data exfiltration. ## Resolution/Fix The issue was confirmed and fixed in the master branch. An official release will be published soon. ## Workarounds Until the release is available, validate and block unsafe URI schemes (e.g., `javascript:`) before rendering Markdown, and enable Parsedown Safe Mode. ## Credits/Acknowledgement Reported by Arkadiusz Marta (https://github.com/arkmarta/).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References (5)