CVE-2026-27568

EPSS 0.01%

AVideo has Stored Cross-Site Scripting via Markdown Comment Injection

發布日:2026/2/20修改日:2026/2/24

描述

## Vulnerability Type Stored Cross-Site Scripting (XSS) — CWE-79. ## Affected Product/Versions AVideo 18.0. ## Root Cause Summary AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficiently sanitized, allowing `javascript:` URIs to be rendered as clickable links. ## Impact Summary An authenticated low-privilege attacker can post a malicious comment that injects persistent JavaScript. When another user clicks the link, the attacker can perform actions such as session hijacking, privilege escalation (including admin takeover), and data exfiltration. ## Resolution/Fix The issue was confirmed and fixed in the master branch. An official release will be published soon. ## Workarounds Until the release is available, validate and block unsafe URI schemes (e.g., `javascript:`) before rendering Markdown, and enable Parsedown Safe Mode. ## Credits/Acknowledgement Reported by Arkadiusz Marta (https://github.com/arkmarta/).

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

參考連結(5)