Local File Disclosure in Kaltura HTML5 Player by Kaltura
CVE-2026-19913
What is CVE-2026-19913?
The Kaltura HTML5 player, specifically through the mwEmbed / html5lib, is susceptible to a local file disclosure vulnerability. This arises from the insufficient validation of the ServiceUrl parameter within mwEmbedLoader.php. The ServiceUrl, intended to serve as a base URL for backend requests, is lax in its restrictions, allowing non-HTTP schemes like 'file://'. Consequently, when an error or exception occurs, the raw contents of the server's internal files are improperly sent back to the client, potentially exposing sensitive data to an unauthenticated remote attacker. Affected versions consist of html5lib v2.45, v2.103, and earlier v2.x releases which include this vulnerable endpoint.
Affected Version(s)
Kaltura HTML5 Video Player, html5lib library 0
Kaltura HTML5 Video Player, html5lib library 2.45
