Cross-Site Scripting Flaw in AVideo with YPTSocket Plugin
CVE-2026-86188
6.9MEDIUM
What is CVE-2026-86188?
The YPTSocket plugin for AVideo is vulnerable to cross-site scripting, enabling unauthenticated attackers to execute arbitrary JavaScript in users' browsers. This threat arises from the plugin's websocket callback mechanism, which allows attackers to send tailored socket messages containing callback names linked to insecure global functions such as avideoConfirmHTML. These functions accept untrusted data and use innerHTML for rendering, creating an avenue for script execution in the victim's browser without authentication or user interaction.
Affected Version(s)
AVideo 0 <= 29.0
