CVE-2026-27568
EPSS 0.01%AVideo has Stored Cross-Site Scripting via Markdown Comment Injection
描述
## Vulnerability Type Stored Cross-Site Scripting (XSS) — CWE-79. ## Affected Product/Versions AVideo 18.0. ## Root Cause Summary AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficiently sanitized, allowing `javascript:` URIs to be rendered as clickable links. ## Impact Summary An authenticated low-privilege attacker can post a malicious comment that injects persistent JavaScript. When another user clicks the link, the attacker can perform actions such as session hijacking, privilege escalation (including admin takeover), and data exfiltration. ## Resolution/Fix The issue was confirmed and fixed in the master branch. An official release will be published soon. ## Workarounds Until the release is available, validate and block unsafe URI schemes (e.g., `javascript:`) before rendering Markdown, and enable Parsedown Safe Mode. ## Credits/Acknowledgement Reported by Arkadiusz Marta (https://github.com/arkmarta/).
受影響套件(1)
- Packagist/wwbn/avideofrom 0, < 21.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |